VYPR

Octopus Server

Sign in to watch

by Octopus

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-11348Med0.375.70.01Jul 17, 2017In Octopus Deploy 3.x before 3.15.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted NuGet package, potentially overwriting other packages or modifying system files. This is a directory traversal in the PackageId value.
CVE-2026-3237Med0.284.30.00Mar 17, 2026In affected versions of Octopus Server it was possible for a low privileged user to manipulate an API request to change the signing key expiration and revocation time frames via an API endpoint that had incorrect permission validation. It was not possible to expose the signing keys using this vulnerability.