Skip to main content

Vendor archive

octopus CVEs

Beta · best-effort

103 CVEs tagged to vendor octopus5 Critical, 31 High, 58 Medium, 9 Low, 0 Unrated.

CVE-2022-29890

Published Jul 15, 2022

In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the support link.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1881

Published Jul 15, 2022

In affected versions of Octopus Server an Insecure Direct Object Reference vulnerability exists where it is possible for a user to download Project Exports from a Project they do…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1670

Published May 19, 2022

When generating a user invitation code in Octopus Server, the validity of this code can be set for a specific number of users. It was possible to bypass this restriction of validi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-1502

Published May 4, 2022

Permissions were not properly verified in the API on projects using version control in Git. This allowed projects to be modified by users with only ProjectView permissions.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31821

Published Jan 19, 2022

When the Windows Tentacle docker image starts up it logs all the commands that it runs along with the arguments, which writes the Octopus Server API key in plaintext. This does no…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31822

Published Nov 24, 2021

When Octopus Tentacle is installed on a Linux operating system, the systemd service file permissions are misconfigured. This could lead to a local unprivileged user modifying the…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-26557

Published Oct 7, 2021

When Octopus Tentacle is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL side-loading to gain privileg…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-31819

Published Sep 22, 2021

In Halibut versions prior to 4.4.7 there is a deserialisation vulnerability that could allow remote code execution on systems that already trust each other based on certificate ve…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-31817

Published Jul 8, 2021

When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the OctopusServer.txt log file in p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-31816

Published Jul 8, 2021

When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the OctopusServer.txt log file in p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-31818

Published Jun 17, 2021

Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API because user supplied data in the API request isn’t parameteri…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-30183

Published May 14, 2021

Cleartext storage of sensitive information in multiple versions of Octopus Server where in certain situations when running import or export processes, the password used to encrypt…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-21270

Published Jan 22, 2021

OctopusDSC is a PowerShell module with DSC resources that can be used to install and configure an Octopus Deploy Server and Tentacle agent. In OctopusDSC version 4.0.977 and earli…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26161

Published Oct 26, 2020

In Octopus Deploy through 2020.4.2, an attacker could redirect users to an external site via a modified HTTP Host header.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-27155

Published Oct 22, 2020

An issue was discovered in Octopus Deploy through 2020.4.4. If enabled, the websocket endpoint may allow an untrusted tentacle host to present itself as a trusted one.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25825

Published Oct 12, 2020

In Octopus Deploy 3.1.0 to 2020.4.0, certain scripts can reveal sensitive information to the user in the task logs.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24566

Published Sep 9, 2020

In Octopus Deploy 2020.3.x before 2020.3.4 and 2020.4.x before 2020.4.1, if an authenticated user creates a deployment or runbook process using Azure steps and sets the step's exe…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-16197

Published Aug 25, 2020

An issue was discovered in Octopus Deploy 3.4. A deployment target can be configured with an Account or Certificate that is outside the scope of the deployment target. An authoris…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-14470

Published Jun 19, 2020

In Octopus Deploy 2018.8.0 through 2019.x before 2019.12.2, an authenticated user with could trigger a deployment that leaks the Helm Chart repository password.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12286

Published Apr 28, 2020

In Octopus Deploy before 2019.12.9 and 2020 before 2020.1.12, the TaskView permission is not scoped to any dimension. For example, a scoped user who is scoped to only one tenant c…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 51-75 of 103 CVEsPage 3 of 5