Vendor CVEs
Octopus
All CVEs
105 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-12884 | Med | 0.42 | 6.5 | 0.01 | Jun 26, 2018 | In Octopus Deploy 3.0 onwards (before 2018.6.7), an authenticated user with incorrect permissions may be able to create Accounts under the Infrastructure menu. | ||
| CVE-2018-9039 | Med | 0.42 | 6.5 | 0.01 | Mar 27, 2018 | In Octopus Deploy 2.0 and later before 2018.3.7, an authenticated user, with variable edit permissions, can scope some variables to targets greater than their permissions should allow. In other words, they can see machines beyond their team's scoped environments. | ||
| CVE-2017-15611 | Med | 0.42 | 6.5 | 0.01 | Oct 19, 2017 | In Octopus before 3.17.7, an authenticated user who was explicitly granted the permission to invite new users (aka UserInvite) can invite users to teams with escalated privileges. | ||
| CVE-2017-15610 | Med | 0.42 | 6.5 | 0.01 | Oct 19, 2017 | An issue was discovered in Octopus before 3.17.7. When the special Guest user account is granted the CertificateExportPrivateKey permission, and Guest Access is enabled for the Octopus Server, an attacker can sign in as the Guest account and export Certificates managed by… | ||
| CVE-2022-3614 | Med | 0.40 | 6.1 | 0.00 | Jan 3, 2023 | In affected versions of Octopus Deploy users of certain browsers using AD to sign-in to Octopus Server were able to bypass authentication checks and be redirected to the configured redirect url without any validation. | ||
| CVE-2022-29890 | Med | 0.40 | 6.1 | 0.00 | Jul 15, 2022 | In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the support link. | ||
| CVE-2022-23184 | Med | 0.40 | 6.1 | 0.01 | Feb 7, 2022 | In affected Octopus Server versions when the server HTTP and HTTPS bindings are configured to localhost, Octopus Server will allow open redirects. | ||
| CVE-2020-26161 | Med | 0.40 | 6.1 | 0.01 | Oct 26, 2020 | In Octopus Deploy through 2020.4.2, an attacker could redirect users to an external site via a modified HTTP Host header. | ||
| CVE-2017-11348 | Med | 0.37 | 5.7 | 0.01 | Jul 17, 2017 | In Octopus Deploy 3.x before 3.15.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted NuGet package, potentially overwriting other packages or modifying system files. This is a directory traversal in the PackageId value. | ||
| CVE-2026-8296 | Med | 0.36 | — | 0.00 | Jun 19, 2026 | In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Payload via artifacts. | ||
| CVE-2022-2416 | Med | 0.36 | 5.5 | 0.00 | Aug 2, 2023 | In affected versions of Octopus Deploy it is possible for a low privileged guest user to craft a request that allows enumeration/recon of an environment. | ||
| CVE-2022-2346 | Med | 0.36 | 5.5 | 0.00 | Aug 2, 2023 | In affected versions of Octopus Deploy it is possible for a low privileged guest user to interact with extension endpoints. | ||
| CVE-2022-4008 | Med | 0.36 | 5.5 | 0.00 | May 10, 2023 | In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service | ||
| CVE-2021-31821 | Med | 0.36 | 5.5 | 0.00 | Jan 19, 2022 | When the Windows Tentacle docker image starts up it logs all the commands that it runs along with the arguments, which writes the Octopus Server API key in plaintext. This does not affect the Linux Docker image | ||
| CVE-2025-0526 | Med | 0.35 | 5.4 | 0.00 | Feb 11, 2025 | In affected versions of Octopus Deploy it was possible to upload files to unexpected locations on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows. | ||
| CVE-2025-0513 | Med | 0.35 | 5.4 | 0.00 | Feb 11, 2025 | In affected versions of Octopus Server error messages were handled unsafely on the error page. If an adversary could control any part of the error message they could embed code which may impact the user viewing the error message. | ||
| CVE-2022-4898 | Med | 0.35 | 5.4 | 0.00 | Jan 31, 2023 | In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the support link. This was initially resolved in advisory 2022-07 however it was identified that the fix could be bypassed in certain circumstances. A different… | ||
| CVE-2019-19085 | Med | 0.35 | 5.4 | 0.01 | Nov 18, 2019 | A persistent cross-site scripting (XSS) vulnerability in Octopus Server 3.4.0 through 2019.10.5 allows remote authenticated attackers to inject arbitrary web script or HTML. | ||
| CVE-2018-10581 | Med | 0.35 | 5.4 | 0.01 | May 1, 2018 | In Octopus Deploy 3.4.x before 2018.4.7, an authenticated user is able to view/update/save variable values within the Tenant Variables area for Environments that do not exist within their associated Team scoping. This occurs in situations where this authenticated user also… | ||
| CVE-2017-16810 | Med | 0.35 | 5.4 | 0.01 | Nov 14, 2017 | Cross-site scripting (XSS) vulnerability in the All Variables tab in Octopus Deploy 3.4.0-3.13.6 (fixed in 3.13.7) allows remote attackers to inject arbitrary web script or HTML via the Variable Set Name parameter. | ||
| CVE-2017-16801 | Med | 0.35 | 5.4 | 0.01 | Nov 13, 2017 | Cross-site scripting (XSS) vulnerability in Octopus Deploy 3.7.0-3.17.13 (fixed in 3.17.14) allows remote authenticated users to inject arbitrary web script or HTML via the Step Template Name parameter. | ||
| CVE-2025-0589 | Med | 0.34 | 5.3 | 0.00 | Feb 11, 2025 | In affected versions of Octopus Deploy where customers are using Active Directory for authentication it was possible for an unauthenticated user to make an API request against two endpoints which would retrieve some data from the associated Active Directory. The requests when… | ||
| CVE-2022-4870 | Med | 0.34 | 5.3 | 0.00 | May 18, 2023 | In affected versions of Octopus Deploy it is possible to discover network details via error message | ||
| CVE-2023-2247 | Med | 0.34 | 5.3 | 0.00 | May 2, 2023 | In affected versions of Octopus Deploy it is possible to unmask variable secrets using the variable preview function | ||
| CVE-2022-2507 | Med | 0.34 | 5.3 | 0.00 | Apr 19, 2023 | In affected versions of Octopus Deploy it is possible to render user supplied input into the webpage | ||
| CVE-2022-2508 | Med | 0.34 | 5.3 | 0.01 | Oct 27, 2022 | In affected versions of Octopus Server it is possible to reveal the existence of resources in a space that the user does not have access to due to verbose error messaging. | ||
| CVE-2022-2720 | Med | 0.34 | 5.3 | 0.00 | Oct 12, 2022 | In affected versions of Octopus Server it was identified that when a sensitive value is a substring of another value, sensitive value masking will only partially work. | ||
| CVE-2022-2783 | Med | 0.34 | 5.3 | 0.00 | Oct 6, 2022 | In affected versions of Octopus Server it was identified that a session cookie could be used as the CSRF token | ||
| CVE-2022-2781 | Med | 0.34 | 5.3 | 0.00 | Oct 6, 2022 | In affected versions of Octopus Server it was identified that the same encryption process was used for both encrypting session cookies and variables. | ||
| CVE-2022-1901 | Med | 0.34 | 5.3 | 0.00 | Aug 19, 2022 | In affected versions of Octopus Deploy it is possible to unmask sensitive variables by using variable preview. | ||
| CVE-2022-30532 | Med | 0.34 | 5.3 | 0.01 | Jul 19, 2022 | In affected versions of Octopus Deploy, there is no logging of changes to artifacts within Octopus Deploy. | ||
| CVE-2022-1881 | Med | 0.34 | 5.3 | 0.01 | Jul 15, 2022 | In affected versions of Octopus Server an Insecure Direct Object Reference vulnerability exists where it is possible for a user to download Project Exports from a Project they do not have permissions to access. This vulnerability only impacts projects within the same Space. | ||
| CVE-2019-19375 | Med | 0.34 | 5.3 | 0.00 | Nov 28, 2019 | In Octopus Deploy before 2019.10.7, in a configuration where SSL offloading is enabled, the CSRF cookie was sometimes sent without the secure attribute. (The fix for this was backported to LTS versions 2019.6.14 and 2019.9.8.) | ||
| CVE-2025-0588 | Med | 0.32 | 4.9 | 0.00 | Feb 11, 2025 | In affected versions of Octopus Server it was possible for a user with sufficient access to set custom headers in all server responses. By submitting a specifically crafted referrer header the user could ensure that all subsequent server responses would return 500 errors… | ||
| CVE-2019-14525 | Med | 0.32 | 4.9 | 0.02 | Aug 5, 2019 | In Octopus Deploy 2019.4.0 through 2019.6.x before 2019.6.6, and 2019.7.x before 2019.7.6, an authenticated system administrator is able to view sensitive values by visiting a server configuration page or making an API call. | ||
| CVE-2026-3237 | Med | 0.28 | 4.3 | 0.00 | Mar 17, 2026 | In affected versions of Octopus Server it was possible for a low privileged user to manipulate an API request to change the signing key expiration and revocation time frames via an API endpoint that had incorrect permission validation. It was not possible to expose the signing… | ||
| CVE-2026-3236 | Med | 0.28 | 4.3 | 0.00 | Mar 5, 2026 | In affected versions of Octopus Server it was possible to create a new API key from an existing access token resulting in the new API key having a lifetime exceeding the original API key used to mint the access token. | ||
| CVE-2023-4509 | Med | 0.28 | 4.3 | 0.00 | Apr 18, 2024 | It is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt. | ||
| CVE-2022-2259 | Med | 0.28 | 4.3 | 0.00 | Mar 13, 2023 | In affected versions of Octopus Deploy it is possible for a user to view Workerpools without being explicitly assigned permissions to view these items | ||
| CVE-2022-2258 | Med | 0.28 | 4.3 | 0.01 | Mar 13, 2023 | In affected versions of Octopus Deploy it is possible for a user to view Tagsets without being explicitly assigned permissions to view these items | ||
| CVE-2022-2760 | Med | 0.28 | 4.3 | 0.00 | Sep 28, 2022 | In affected versions of Octopus Deploy it is possible to reveal the Space ID of spaces that the user does not have access to view in an error message when a resource is part of another Space. | ||
| CVE-2022-1502 | Med | 0.28 | 4.3 | 0.01 | May 4, 2022 | Permissions were not properly verified in the API on projects using version control in Git. This allowed projects to be modified by users with only ProjectView permissions. | ||
| CVE-2021-31818 | Med | 0.28 | 4.3 | 0.01 | Jun 17, 2021 | Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API because user supplied data in the API request isn’t parameterised correctly. Exploiting this vulnerability could allow unauthorised access to database tables. | ||
| CVE-2020-16197 | Med | 0.28 | 4.3 | 0.01 | Aug 25, 2020 | An issue was discovered in Octopus Deploy 3.4. A deployment target can be configured with an Account or Certificate that is outside the scope of the deployment target. An authorised user can potentially use a certificate that they are not in scope to use. An authorised user is… | ||
| CVE-2020-12286 | Med | 0.28 | 4.3 | 0.01 | Apr 28, 2020 | In Octopus Deploy before 2019.12.9 and 2020 before 2020.1.12, the TaskView permission is not scoped to any dimension. For example, a scoped user who is scoped to only one tenant can view server tasks scoped to any other tenant. | ||
| CVE-2019-19084 | Med | 0.28 | 4.3 | 0.01 | Nov 18, 2019 | In Octopus Deploy 3.3.0 through 2019.10.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted package, triggering an exception that exposes underlying operating system details. | ||
| CVE-2019-15698 | Med | 0.28 | 4.3 | 0.01 | Aug 27, 2019 | In Octopus Deploy 2019.7.3 through 2019.7.9, in certain circumstances, an authenticated user with VariableView permissions could view sensitive values. This is fixed in 2019.7.10. | ||
| CVE-2024-4456 | Med | 0.27 | 4.1 | 0.00 | May 8, 2024 | In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting payload on the audit page. | ||
| CVE-2023-1904 | Med | 0.27 | 4.2 | 0.00 | Dec 14, 2023 | In affected versions of Octopus Server it is possible for the OpenID client secret to be logged in clear text during the configuration of Octopus Server. | ||
| CVE-2024-4226 | Low | 0.23 | 3.5 | 0.00 | Apr 30, 2024 | It was identified that in certain versions of Octopus Server, that a user created with no permissions could view all users, user roles and permissions. This functionality was removed in versions of Octopus Server after the fixed versions listed. |
- risk 0.42cvss 6.5epss 0.01
In Octopus Deploy 3.0 onwards (before 2018.6.7), an authenticated user with incorrect permissions may be able to create Accounts under the Infrastructure menu.
- risk 0.42cvss 6.5epss 0.01
In Octopus Deploy 2.0 and later before 2018.3.7, an authenticated user, with variable edit permissions, can scope some variables to targets greater than their permissions should allow. In other words, they can see machines beyond their team's scoped environments.
- risk 0.42cvss 6.5epss 0.01
In Octopus before 3.17.7, an authenticated user who was explicitly granted the permission to invite new users (aka UserInvite) can invite users to teams with escalated privileges.
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in Octopus before 3.17.7. When the special Guest user account is granted the CertificateExportPrivateKey permission, and Guest Access is enabled for the Octopus Server, an attacker can sign in as the Guest account and export Certificates managed by…
- risk 0.40cvss 6.1epss 0.00
In affected versions of Octopus Deploy users of certain browsers using AD to sign-in to Octopus Server were able to bypass authentication checks and be redirected to the configured redirect url without any validation.
- risk 0.40cvss 6.1epss 0.00
In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the support link.
- risk 0.40cvss 6.1epss 0.01
In affected Octopus Server versions when the server HTTP and HTTPS bindings are configured to localhost, Octopus Server will allow open redirects.
- risk 0.40cvss 6.1epss 0.01
In Octopus Deploy through 2020.4.2, an attacker could redirect users to an external site via a modified HTTP Host header.
- risk 0.37cvss 5.7epss 0.01
In Octopus Deploy 3.x before 3.15.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted NuGet package, potentially overwriting other packages or modifying system files. This is a directory traversal in the PackageId value.
- risk 0.36cvss —epss 0.00
In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Payload via artifacts.
- risk 0.36cvss 5.5epss 0.00
In affected versions of Octopus Deploy it is possible for a low privileged guest user to craft a request that allows enumeration/recon of an environment.
- risk 0.36cvss 5.5epss 0.00
In affected versions of Octopus Deploy it is possible for a low privileged guest user to interact with extension endpoints.
- risk 0.36cvss 5.5epss 0.00
In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service
- risk 0.36cvss 5.5epss 0.00
When the Windows Tentacle docker image starts up it logs all the commands that it runs along with the arguments, which writes the Octopus Server API key in plaintext. This does not affect the Linux Docker image
- risk 0.35cvss 5.4epss 0.00
In affected versions of Octopus Deploy it was possible to upload files to unexpected locations on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows.
- risk 0.35cvss 5.4epss 0.00
In affected versions of Octopus Server error messages were handled unsafely on the error page. If an adversary could control any part of the error message they could embed code which may impact the user viewing the error message.
- risk 0.35cvss 5.4epss 0.00
In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the support link. This was initially resolved in advisory 2022-07 however it was identified that the fix could be bypassed in certain circumstances. A different…
- risk 0.35cvss 5.4epss 0.01
A persistent cross-site scripting (XSS) vulnerability in Octopus Server 3.4.0 through 2019.10.5 allows remote authenticated attackers to inject arbitrary web script or HTML.
- risk 0.35cvss 5.4epss 0.01
In Octopus Deploy 3.4.x before 2018.4.7, an authenticated user is able to view/update/save variable values within the Tenant Variables area for Environments that do not exist within their associated Team scoping. This occurs in situations where this authenticated user also…
- risk 0.35cvss 5.4epss 0.01
Cross-site scripting (XSS) vulnerability in the All Variables tab in Octopus Deploy 3.4.0-3.13.6 (fixed in 3.13.7) allows remote attackers to inject arbitrary web script or HTML via the Variable Set Name parameter.
- risk 0.35cvss 5.4epss 0.01
Cross-site scripting (XSS) vulnerability in Octopus Deploy 3.7.0-3.17.13 (fixed in 3.17.14) allows remote authenticated users to inject arbitrary web script or HTML via the Step Template Name parameter.
- risk 0.34cvss 5.3epss 0.00
In affected versions of Octopus Deploy where customers are using Active Directory for authentication it was possible for an unauthenticated user to make an API request against two endpoints which would retrieve some data from the associated Active Directory. The requests when…
- risk 0.34cvss 5.3epss 0.00
In affected versions of Octopus Deploy it is possible to discover network details via error message
- risk 0.34cvss 5.3epss 0.00
In affected versions of Octopus Deploy it is possible to unmask variable secrets using the variable preview function
- risk 0.34cvss 5.3epss 0.00
In affected versions of Octopus Deploy it is possible to render user supplied input into the webpage
- risk 0.34cvss 5.3epss 0.01
In affected versions of Octopus Server it is possible to reveal the existence of resources in a space that the user does not have access to due to verbose error messaging.
- risk 0.34cvss 5.3epss 0.00
In affected versions of Octopus Server it was identified that when a sensitive value is a substring of another value, sensitive value masking will only partially work.
- risk 0.34cvss 5.3epss 0.00
In affected versions of Octopus Server it was identified that a session cookie could be used as the CSRF token
- risk 0.34cvss 5.3epss 0.00
In affected versions of Octopus Server it was identified that the same encryption process was used for both encrypting session cookies and variables.
- risk 0.34cvss 5.3epss 0.00
In affected versions of Octopus Deploy it is possible to unmask sensitive variables by using variable preview.
- risk 0.34cvss 5.3epss 0.01
In affected versions of Octopus Deploy, there is no logging of changes to artifacts within Octopus Deploy.
- risk 0.34cvss 5.3epss 0.01
In affected versions of Octopus Server an Insecure Direct Object Reference vulnerability exists where it is possible for a user to download Project Exports from a Project they do not have permissions to access. This vulnerability only impacts projects within the same Space.
- risk 0.34cvss 5.3epss 0.00
In Octopus Deploy before 2019.10.7, in a configuration where SSL offloading is enabled, the CSRF cookie was sometimes sent without the secure attribute. (The fix for this was backported to LTS versions 2019.6.14 and 2019.9.8.)
- risk 0.32cvss 4.9epss 0.00
In affected versions of Octopus Server it was possible for a user with sufficient access to set custom headers in all server responses. By submitting a specifically crafted referrer header the user could ensure that all subsequent server responses would return 500 errors…
- risk 0.32cvss 4.9epss 0.02
In Octopus Deploy 2019.4.0 through 2019.6.x before 2019.6.6, and 2019.7.x before 2019.7.6, an authenticated system administrator is able to view sensitive values by visiting a server configuration page or making an API call.
- risk 0.28cvss 4.3epss 0.00
In affected versions of Octopus Server it was possible for a low privileged user to manipulate an API request to change the signing key expiration and revocation time frames via an API endpoint that had incorrect permission validation. It was not possible to expose the signing…
- risk 0.28cvss 4.3epss 0.00
In affected versions of Octopus Server it was possible to create a new API key from an existing access token resulting in the new API key having a lifetime exceeding the original API key used to mint the access token.
- risk 0.28cvss 4.3epss 0.00
It is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt.
- risk 0.28cvss 4.3epss 0.00
In affected versions of Octopus Deploy it is possible for a user to view Workerpools without being explicitly assigned permissions to view these items
- risk 0.28cvss 4.3epss 0.01
In affected versions of Octopus Deploy it is possible for a user to view Tagsets without being explicitly assigned permissions to view these items
- risk 0.28cvss 4.3epss 0.00
In affected versions of Octopus Deploy it is possible to reveal the Space ID of spaces that the user does not have access to view in an error message when a resource is part of another Space.
- risk 0.28cvss 4.3epss 0.01
Permissions were not properly verified in the API on projects using version control in Git. This allowed projects to be modified by users with only ProjectView permissions.
- risk 0.28cvss 4.3epss 0.01
Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API because user supplied data in the API request isn’t parameterised correctly. Exploiting this vulnerability could allow unauthorised access to database tables.
- risk 0.28cvss 4.3epss 0.01
An issue was discovered in Octopus Deploy 3.4. A deployment target can be configured with an Account or Certificate that is outside the scope of the deployment target. An authorised user can potentially use a certificate that they are not in scope to use. An authorised user is…
- risk 0.28cvss 4.3epss 0.01
In Octopus Deploy before 2019.12.9 and 2020 before 2020.1.12, the TaskView permission is not scoped to any dimension. For example, a scoped user who is scoped to only one tenant can view server tasks scoped to any other tenant.
- risk 0.28cvss 4.3epss 0.01
In Octopus Deploy 3.3.0 through 2019.10.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted package, triggering an exception that exposes underlying operating system details.
- risk 0.28cvss 4.3epss 0.01
In Octopus Deploy 2019.7.3 through 2019.7.9, in certain circumstances, an authenticated user with VariableView permissions could view sensitive values. This is fixed in 2019.7.10.
- risk 0.27cvss 4.1epss 0.00
In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting payload on the audit page.
- risk 0.27cvss 4.2epss 0.00
In affected versions of Octopus Server it is possible for the OpenID client secret to be logged in clear text during the configuration of Octopus Server.
- risk 0.23cvss 3.5epss 0.00
It was identified that in certain versions of Octopus Server, that a user created with no permissions could view all users, user roles and permissions. This functionality was removed in versions of Octopus Server after the fixed versions listed.
Page 2 of 3