Permissions were not properly verified in the API on projects using version control in Git. This allowed projects to be modified by users with only ProjectView permissions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Server | Octopus | 2021.3 (including) | 2021.3.12725 (excluding) |
Server | Octopus | 2022.1 (including) | 2022.1.2454 (excluding) |