CVE Database
/

CVE-2021-26556

Back to search

CVE-2021-26556

Published: Oct 7, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

When Octopus Server is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL side-loading to gain privileged access.

VendorProductVersions

Octopus Deploy

Octopus Server

affected
0.9 - < unspecified
affected
unspecified - < 2020.4.229
affected
2020.5.0 - < unspecified
affected
unspecified - < 2020.5.256

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now