In Octopus Deploy before 2020.1.5, for customers running on-premises Active Directory linked to their Octopus server, an authenticated user can leverage a bug to escalate privileges.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Octopus_deploy | Octopus | * | 2020.1.5 (excluding) |
References