In affected versions of Octopus Deploy it is possible for a low privileged guest user to interact with extension endpoints.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Octopus_server | Octopus | 2019.4.0 (including) | 2022.4.9997 (excluding) |
Octopus_server | Octopus | 2023.1.4189 (including) | 2023.1.10235 (excluding) |
Octopus_server | Octopus | 2023.2.2028 (including) | 2023.2.10545 (excluding) |