#VU38688 Path traversal in Octopus Deploy - CVE-2017-11348
Published: July 17, 2017 / Updated: August 8, 2020
Octopus Deploy
Octopus Deploy
Description
The vulnerability allows a remote authenticated user to manipulate data.
In Octopus Deploy 3.x before 3.15.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted NuGet package, potentially overwriting other packages or modifying system files. This is a directory traversal in the PackageId value.