VYPR
Medium severity4.3NVD Advisory· Published Aug 25, 2020· Updated Jun 17, 2026

CVE-2020-16197

CVE-2020-16197

Description

An issue was discovered in Octopus Deploy 3.4. A deployment target can be configured with an Account or Certificate that is outside the scope of the deployment target. An authorised user can potentially use a certificate that they are not in scope to use. An authorised user is also able to obtain certificate metadata by associating a certificate with certain resources that should fail scope validation.

Affected products

4
  • Octopus/Server2 versions
    cpe:2.3:a:octopus:octopus_server:3.4.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:octopus:octopus_server:3.4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:octopus:server:3.4.0:*:*:*:*:*:*:*
  • Octopus Deploy/Octopus Deploydescription
  • Range: <3.4

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.