CVE-2018-10550: Octopus Deploy
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
In Octopus Deploy before 2018.4.7, target and tenant tag variable scopes were not checked against the list of tenants the user has access to.
Affected products
- Octopus Octopus Deploy: before 2018.4.7 (fixed in 2018.4.7)
Published 2018-04-30. Last modified 2026-06-17.