CVE-2020-12286: Octopus Deploy
Medium severity, CVSS 4.3. EPSS: 1% chance of exploitation in the next 30 days.
In Octopus Deploy before 2019.12.9 and 2020 before 2020.1.12, the TaskView permission is not scoped to any dimension. For example, a scoped user who is scoped to only one tenant can view server tasks scoped to any other tenant.
Affected products
- Octopus Octopus Deploy: before 2019.12.9 (fixed in 2019.12.9); from 2020.1, before 2020.1.12 (fixed in 2020.1.12)
Published 2020-04-28. Last modified 2026-06-17.