CVE-2017-11348

Description

In Octopus Deploy 3.x before 3.15.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted NuGet package, potentially overwriting other packages or modifying system files. This is a directory traversal in the PackageId value.

Risk Information

Base Score
5.7
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.626

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.0.0Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.0.1Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.0.10Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.0.11Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.0.12Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.0.13Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.0.14Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.0.15Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.0.16Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.0.17Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.0.18Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.0.19Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.0.2Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.0.20Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.0.21Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.0.22Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.0.23Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.0.24Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.0.25Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.0.26Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.0.3Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.0.4Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.0.5Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.0.6Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.0.7Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.0.8Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.0.9Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.1.0Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.1.0.beta0001Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.1.0.beta0002Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.1.1Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.1.12Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.1.13Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.1.2Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.1.3Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.1.4Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.1.5Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.1.6Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.1.7Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.10.0Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.10.1Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.11.0Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.11.1Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.11.10Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.11.11Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.11.12Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.11.13Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.11.14Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.11.15Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.11.16Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.11.17Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.11.18Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.11.2Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.11.3Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.11.4Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.11.5Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.11.6Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.11.7Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.11.9Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.12.0Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.12.1Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.12.2Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.12.3Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.12.4Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.12.5Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.12.6Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.12.7Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.12.9Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.13.0Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.13.1Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.13.10Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.13.2Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.13.3Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.13.5Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.13.6Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.13.7Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.13.9Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.14.1Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.14.15Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.14.159Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.14.1592Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.14.15926Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.15.0Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.15.1Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.15.2Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.15.3Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.2.0Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.2.0.beta0001Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.2.1Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.2.10Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.2.11Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.2.15Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.2.16Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.2.17Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.2.19Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.2.2Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.2.20Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.2.21Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.2.22Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.2.23Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.2.24Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.2.3Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.2.4Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.2.6Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.2.7Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.2.8Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.2.9Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.3.0Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.3.0.beta0001Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.3.0.beta0002Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.3.1Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.3.10Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.3.11Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.3.12Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.3.14Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.3.15Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.3.16Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.3.17Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.3.18Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.3.19Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.3.2Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.3.20Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.3.21Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.3.22Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.3.24Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.3.25Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.3.26Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.3.27Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.3.3Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.3.4Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.3.5Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.3.6Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.3.8Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.3.9Windows
Vulnerabilities CVE-2017-11348,CVE-2020-16197 are affected in Octopus Server 3.4.0Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.4.0.beta0001Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.4.0.beta0002Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.4.1Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.4.10Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.4.11Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.4.12Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.4.13Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.4.14Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.4.15Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.4.3Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.4.4Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.4.5Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.4.6Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.4.7Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.4.8Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.4.9Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.5.1Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.5.2Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.5.4Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.5.5Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.5.6Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.5.7Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.5.8Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.5.9Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.6.1Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.6.2Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.7.1Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.7.10Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.7.11Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.7.12Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.7.13Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.7.14Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.7.15Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.7.16Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.7.17Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.7.18Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.7.2Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.7.3Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.7.4Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.7.5Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.7.6Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.7.7Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.7.8Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.7.9Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.8.0Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.8.1Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.8.2Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.8.3Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.8.4Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.8.5Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.8.6Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.8.7Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.8.8Windows
Vulnerabilities CVE-2017-11348 are affected in Octopus Server 3.8.9Windows
Vulnerabilities CVE-2017-11348,CVE-2022-2049,CVE-2022-2074,CVE-2022-2075 are affected in Octopus Server 3.9.0Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234