Files
CVEs-PoC/2020/CVE-2020-12286.md
T
2025-09-29 21:09:30 +02:00

712 B

CVE-2020-12286

Description

In Octopus Deploy before 2019.12.9 and 2020 before 2020.1.12, the TaskView permission is not scoped to any dimension. For example, a scoped user who is scoped to only one tenant can view server tasks scoped to any other tenant.

POC

Reference

Github

No PoCs found on GitHub currently.