Aller au contenu principal
HIGH

CVE-2018-18850

CVSS v3

8.8

HIGH

Score EPSS

12.5 %

probabilité d’exploitation au 2026-10-05

CISA KEV

Non

exploitation connue

Exploitation

—

statut SSVC

Description

In Octopus Deploy 2018.8.0 through 2018.9.x before 2018.9.1, an authenticated user with permission to modify deployment processes could upload a maliciously crafted YAML configuration, potentially allowing for remote execution of arbitrary code, running in the same context as the Octopus Server (for self-hosted installations by default, SYSTEM).

Détails techniques

Publiée le
2018-10-31

Questions fréquentes

Qu’est-ce que CVE-2018-18850 ?

In Octopus Deploy 2018.8.0 through 2018.9.x before 2018.9.1, an authenticated user with permission to modify deployment processes could upload a maliciously crafted YAML configuration, potentially allowing for remote execution of arbitrary code, running in the same context as the Octopus Server (for self-hosted installations by default, SYSTEM).

CVE-2018-18850 est-elle activement exploitée ?

Aucune exploitation active de CVE-2018-18850 n’est confirmée. Son score EPSS était de 12.5 % au 2026-10-05, soit la probabilité estimée d’exploitation dans les 30 prochains jours.

Quel est le score CVSS de CVE-2018-18850 ?

CVE-2018-18850 a un score de base CVSS v3 de 8.8 (gravité HIGH).

CVE-2018-18850 touche-t-elle votre environnement ?

Utilisez isMalicious pour vérifier si l’une de vos IP ou l’un de vos domaines est associé aux IOC de cette vulnérabilité.

Sans carte bancaire · 50 vérifications gratuites par mois · Clé API gratuite