Octopusdeploy
by Octopus
Source repositories
CVEs (63)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-2346 | Med | 0.36 | 5.5 | 0.00 | Aug 2, 2023 | In affected versions of Octopus Deploy it is possible for a low privileged guest user to interact with extension endpoints. | ||
| CVE-2022-4008 | Med | 0.36 | 5.5 | 0.00 | May 10, 2023 | In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service | ||
| CVE-2025-0526 | Med | 0.35 | 5.4 | 0.00 | Feb 11, 2025 | In affected versions of Octopus Deploy it was possible to upload files to unexpected locations on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows. | ||
| CVE-2018-10581 | Med | 0.35 | 5.4 | 0.01 | May 1, 2018 | In Octopus Deploy 3.4.x before 2018.4.7, an authenticated user is able to view/update/save variable values within the Tenant Variables area for Environments that do not exist within their associated Team scoping. This occurs in situations where this authenticated user also… | ||
| CVE-2017-16810 | Med | 0.35 | 5.4 | 0.01 | Nov 14, 2017 | Cross-site scripting (XSS) vulnerability in the All Variables tab in Octopus Deploy 3.4.0-3.13.6 (fixed in 3.13.7) allows remote attackers to inject arbitrary web script or HTML via the Variable Set Name parameter. | ||
| CVE-2017-16801 | Med | 0.35 | 5.4 | 0.01 | Nov 13, 2017 | Cross-site scripting (XSS) vulnerability in Octopus Deploy 3.7.0-3.17.13 (fixed in 3.17.14) allows remote authenticated users to inject arbitrary web script or HTML via the Step Template Name parameter. | ||
| CVE-2025-0589 | Med | 0.34 | 5.3 | 0.00 | Feb 11, 2025 | In affected versions of Octopus Deploy where customers are using Active Directory for authentication it was possible for an unauthenticated user to make an API request against two endpoints which would retrieve some data from the associated Active Directory. The requests when… | ||
| CVE-2022-4870 | Med | 0.34 | 5.3 | 0.00 | May 18, 2023 | In affected versions of Octopus Deploy it is possible to discover network details via error message | ||
| CVE-2023-2247 | Med | 0.34 | 5.3 | 0.00 | May 2, 2023 | In affected versions of Octopus Deploy it is possible to unmask variable secrets using the variable preview function | ||
| CVE-2022-2507 | Med | 0.34 | 5.3 | 0.00 | Apr 19, 2023 | In affected versions of Octopus Deploy it is possible to render user supplied input into the webpage | ||
| CVE-2022-1901 | Med | 0.34 | 5.3 | 0.01 | Aug 19, 2022 | In affected versions of Octopus Deploy it is possible to unmask sensitive variables by using variable preview. | ||
| CVE-2022-30532 | Med | 0.34 | 5.3 | 0.01 | Jul 19, 2022 | In affected versions of Octopus Deploy, there is no logging of changes to artifacts within Octopus Deploy. | ||
| CVE-2019-19375 | Med | 0.34 | 5.3 | 0.00 | Nov 28, 2019 | In Octopus Deploy before 2019.10.7, in a configuration where SSL offloading is enabled, the CSRF cookie was sometimes sent without the secure attribute. (The fix for this was backported to LTS versions 2019.6.14 and 2019.9.8.) | ||
| CVE-2026-12702 | Med | 0.32 | 4.9 | 0.00 | Jul 24, 2026 | In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment. | ||
| CVE-2019-14525 | Med | 0.32 | 4.9 | 0.02 | Aug 5, 2019 | In Octopus Deploy 2019.4.0 through 2019.6.x before 2019.6.6, and 2019.7.x before 2019.7.6, an authenticated system administrator is able to view sensitive values by visiting a server configuration page or making an API call. | ||
| CVE-2023-4509 | Med | 0.28 | 4.3 | 0.00 | Apr 18, 2024 | It is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt. | ||
| CVE-2022-2259 | Med | 0.28 | 4.3 | 0.00 | Mar 13, 2023 | In affected versions of Octopus Deploy it is possible for a user to view Workerpools without being explicitly assigned permissions to view these items | ||
| CVE-2022-2258 | Med | 0.28 | 4.3 | 0.01 | Mar 13, 2023 | In affected versions of Octopus Deploy it is possible for a user to view Tagsets without being explicitly assigned permissions to view these items | ||
| CVE-2022-2760 | Med | 0.28 | 4.3 | 0.00 | Sep 28, 2022 | In affected versions of Octopus Deploy it is possible to reveal the Space ID of spaces that the user does not have access to view in an error message when a resource is part of another Space. | ||
| CVE-2020-16197 | Med | 0.28 | 4.3 | 0.01 | Aug 25, 2020 | An issue was discovered in Octopus Deploy 3.4. A deployment target can be configured with an Account or Certificate that is outside the scope of the deployment target. An authorised user can potentially use a certificate that they are not in scope to use. An authorised user is… |
- risk 0.36cvss 5.5epss 0.00
In affected versions of Octopus Deploy it is possible for a low privileged guest user to interact with extension endpoints.
- risk 0.36cvss 5.5epss 0.00
In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service
- risk 0.35cvss 5.4epss 0.00
In affected versions of Octopus Deploy it was possible to upload files to unexpected locations on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows.
- risk 0.35cvss 5.4epss 0.01
In Octopus Deploy 3.4.x before 2018.4.7, an authenticated user is able to view/update/save variable values within the Tenant Variables area for Environments that do not exist within their associated Team scoping. This occurs in situations where this authenticated user also…
- risk 0.35cvss 5.4epss 0.01
Cross-site scripting (XSS) vulnerability in the All Variables tab in Octopus Deploy 3.4.0-3.13.6 (fixed in 3.13.7) allows remote attackers to inject arbitrary web script or HTML via the Variable Set Name parameter.
- risk 0.35cvss 5.4epss 0.01
Cross-site scripting (XSS) vulnerability in Octopus Deploy 3.7.0-3.17.13 (fixed in 3.17.14) allows remote authenticated users to inject arbitrary web script or HTML via the Step Template Name parameter.
- risk 0.34cvss 5.3epss 0.00
In affected versions of Octopus Deploy where customers are using Active Directory for authentication it was possible for an unauthenticated user to make an API request against two endpoints which would retrieve some data from the associated Active Directory. The requests when…
- risk 0.34cvss 5.3epss 0.00
In affected versions of Octopus Deploy it is possible to discover network details via error message
- risk 0.34cvss 5.3epss 0.00
In affected versions of Octopus Deploy it is possible to unmask variable secrets using the variable preview function
- risk 0.34cvss 5.3epss 0.00
In affected versions of Octopus Deploy it is possible to render user supplied input into the webpage
- risk 0.34cvss 5.3epss 0.01
In affected versions of Octopus Deploy it is possible to unmask sensitive variables by using variable preview.
- risk 0.34cvss 5.3epss 0.01
In affected versions of Octopus Deploy, there is no logging of changes to artifacts within Octopus Deploy.
- risk 0.34cvss 5.3epss 0.00
In Octopus Deploy before 2019.10.7, in a configuration where SSL offloading is enabled, the CSRF cookie was sometimes sent without the secure attribute. (The fix for this was backported to LTS versions 2019.6.14 and 2019.9.8.)
- risk 0.32cvss 4.9epss 0.00
In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment.
- risk 0.32cvss 4.9epss 0.02
In Octopus Deploy 2019.4.0 through 2019.6.x before 2019.6.6, and 2019.7.x before 2019.7.6, an authenticated system administrator is able to view sensitive values by visiting a server configuration page or making an API call.
- risk 0.28cvss 4.3epss 0.00
It is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt.
- risk 0.28cvss 4.3epss 0.00
In affected versions of Octopus Deploy it is possible for a user to view Workerpools without being explicitly assigned permissions to view these items
- risk 0.28cvss 4.3epss 0.01
In affected versions of Octopus Deploy it is possible for a user to view Tagsets without being explicitly assigned permissions to view these items
- risk 0.28cvss 4.3epss 0.00
In affected versions of Octopus Deploy it is possible to reveal the Space ID of spaces that the user does not have access to view in an error message when a resource is part of another Space.
- risk 0.28cvss 4.3epss 0.01
An issue was discovered in Octopus Deploy 3.4. A deployment target can be configured with an Account or Certificate that is outside the scope of the deployment target. An authorised user can potentially use a certificate that they are not in scope to use. An authorised user is…
Page 3 of 4