{"api_version":"1","generated_at":"2026-07-23T13:25:41+00:00","cve":"CVE-2018-9039","urls":{"html":"https://cve.report/CVE-2018-9039","api":"https://cve.report/api/cve/CVE-2018-9039.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-9039","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-9039"},"summary":{"title":"CVE-2018-9039","description":"In Octopus Deploy 2.0 and later before 2018.3.7, an authenticated user, with variable edit permissions, can scope some variables to targets greater than their permissions should allow. In other words, they can see machines beyond their team's scoped environments.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2018-03-27 03:29:00","updated_at":"2020-08-24 17:37:00"},"problem_types":["CWE-862"],"metrics":[],"references":[{"url":"https://octopus.com/downloads/compare?from=2018.3.6&to=2018.3.7","name":"https://octopus.com/downloads/compare?from=2018.3.6&to=2018.3.7","refsource":"CONFIRM","tags":["Release Notes"],"title":"2018.3.6 vs. 2018.3.7 - Release Notes - Octopus Deploy","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/OctopusDeploy/Issues/issues/4407","name":"https://github.com/OctopusDeploy/Issues/issues/4407","refsource":"CONFIRM","tags":["Exploit","Third Party Advisory"],"title":"Deployment Targets visible when scoping Project/Library Variable sets for logged-in Users whose Team is not scoped to the required Environments · Issue #4407 · OctopusDeploy/Issues · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-9039","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-9039","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"9039","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"octopus","cpe5":"octopus_deploy","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"9039","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"octopus","cpe5":"octopus_deploy","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2018-9039","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In Octopus Deploy 2.0 and later before 2018.3.7, an authenticated user, with variable edit permissions, can scope some variables to targets greater than their permissions should allow. In other words, they can see machines beyond their team's scoped environments."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://github.com/OctopusDeploy/Issues/issues/4407","refsource":"CONFIRM","url":"https://github.com/OctopusDeploy/Issues/issues/4407"},{"name":"https://octopus.com/downloads/compare?from=2018.3.6&to=2018.3.7","refsource":"CONFIRM","url":"https://octopus.com/downloads/compare?from=2018.3.6&to=2018.3.7"}]}},"nvd":{"publishedDate":"2018-03-27 03:29:00","lastModifiedDate":"2020-08-24 17:37:00","problem_types":["CWE-862"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:octopus:octopus_deploy:*:*:*:*:*:*:*:*","versionStartIncluding":"2.0","versionEndExcluding":"2018.3.7","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"9039","Ordinal":"125425","Title":"CVE-2018-9039","CVE":"CVE-2018-9039","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"9039","Ordinal":"1","NoteData":"In Octopus Deploy 2.0 and later before 2018.3.7, an authenticated user, with variable edit permissions, can scope some variables to targets greater than their permissions should allow. In other words, they can see machines beyond their team's scoped environments.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"9039","Ordinal":"2","NoteData":"2018-03-26","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"9039","Ordinal":"3","NoteData":"2018-03-26","Type":"Other","Title":"Modified"}]}}}