VYPR

Vendor CVEs

Octopus

All CVEs

105 total · sorted by risk
  • CVE-2018-12884MedJun 26, 2018
    risk 0.42cvss 6.5epss 0.01

    In Octopus Deploy 3.0 onwards (before 2018.6.7), an authenticated user with incorrect permissions may be able to create Accounts under the Infrastructure menu.

  • CVE-2018-9039MedMar 27, 2018
    risk 0.42cvss 6.5epss 0.01

    In Octopus Deploy 2.0 and later before 2018.3.7, an authenticated user, with variable edit permissions, can scope some variables to targets greater than their permissions should allow. In other words, they can see machines beyond their team's scoped environments.

  • CVE-2017-15611MedOct 19, 2017
    risk 0.42cvss 6.5epss 0.01

    In Octopus before 3.17.7, an authenticated user who was explicitly granted the permission to invite new users (aka UserInvite) can invite users to teams with escalated privileges.

  • CVE-2017-15610MedOct 19, 2017
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Octopus before 3.17.7. When the special Guest user account is granted the CertificateExportPrivateKey permission, and Guest Access is enabled for the Octopus Server, an attacker can sign in as the Guest account and export Certificates managed by…

  • CVE-2022-3614MedJan 3, 2023
    risk 0.40cvss 6.1epss 0.00

    In affected versions of Octopus Deploy users of certain browsers using AD to sign-in to Octopus Server were able to bypass authentication checks and be redirected to the configured redirect url without any validation.

  • CVE-2022-29890MedJul 15, 2022
    risk 0.40cvss 6.1epss 0.00

    In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the support link.

  • CVE-2022-23184MedFeb 7, 2022
    risk 0.40cvss 6.1epss 0.01

    In affected Octopus Server versions when the server HTTP and HTTPS bindings are configured to localhost, Octopus Server will allow open redirects.

  • CVE-2020-26161MedOct 26, 2020
    risk 0.40cvss 6.1epss 0.01

    In Octopus Deploy through 2020.4.2, an attacker could redirect users to an external site via a modified HTTP Host header.

  • CVE-2017-11348MedJul 17, 2017
    risk 0.37cvss 5.7epss 0.01

    In Octopus Deploy 3.x before 3.15.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted NuGet package, potentially overwriting other packages or modifying system files. This is a directory traversal in the PackageId value.

  • CVE-2026-8296MedJun 19, 2026
    risk 0.36cvss epss 0.00

    In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Payload via artifacts.

  • CVE-2022-2416MedAug 2, 2023
    risk 0.36cvss 5.5epss 0.00

    In affected versions of Octopus Deploy it is possible for a low privileged guest user to craft a request that allows enumeration/recon of an environment.

  • CVE-2022-2346MedAug 2, 2023
    risk 0.36cvss 5.5epss 0.00

    In affected versions of Octopus Deploy it is possible for a low privileged guest user to interact with extension endpoints.

  • CVE-2022-4008MedMay 10, 2023
    risk 0.36cvss 5.5epss 0.00

    In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service

  • CVE-2021-31821MedJan 19, 2022
    risk 0.36cvss 5.5epss 0.00

    When the Windows Tentacle docker image starts up it logs all the commands that it runs along with the arguments, which writes the Octopus Server API key in plaintext. This does not affect the Linux Docker image

  • CVE-2025-0526MedFeb 11, 2025
    risk 0.35cvss 5.4epss 0.00

    In affected versions of Octopus Deploy it was possible to upload files to unexpected locations on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows.

  • CVE-2025-0513MedFeb 11, 2025
    risk 0.35cvss 5.4epss 0.00

    In affected versions of Octopus Server error messages were handled unsafely on the error page. If an adversary could control any part of the error message they could embed code which may impact the user viewing the error message.

  • CVE-2022-4898MedJan 31, 2023
    risk 0.35cvss 5.4epss 0.00

    In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the support link. This was initially resolved in advisory 2022-07 however it was identified that the fix could be bypassed in certain circumstances. A different…

  • CVE-2019-19085MedNov 18, 2019
    risk 0.35cvss 5.4epss 0.01

    A persistent cross-site scripting (XSS) vulnerability in Octopus Server 3.4.0 through 2019.10.5 allows remote authenticated attackers to inject arbitrary web script or HTML.

  • CVE-2018-10581MedMay 1, 2018
    risk 0.35cvss 5.4epss 0.01

    In Octopus Deploy 3.4.x before 2018.4.7, an authenticated user is able to view/update/save variable values within the Tenant Variables area for Environments that do not exist within their associated Team scoping. This occurs in situations where this authenticated user also…

  • CVE-2017-16810MedNov 14, 2017
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in the All Variables tab in Octopus Deploy 3.4.0-3.13.6 (fixed in 3.13.7) allows remote attackers to inject arbitrary web script or HTML via the Variable Set Name parameter.

  • CVE-2017-16801MedNov 13, 2017
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in Octopus Deploy 3.7.0-3.17.13 (fixed in 3.17.14) allows remote authenticated users to inject arbitrary web script or HTML via the Step Template Name parameter.

  • CVE-2025-0589MedFeb 11, 2025
    risk 0.34cvss 5.3epss 0.00

    In affected versions of Octopus Deploy where customers are using Active Directory for authentication it was possible for an unauthenticated user to make an API request against two endpoints which would retrieve some data from the associated Active Directory. The requests when…

  • CVE-2022-4870MedMay 18, 2023
    risk 0.34cvss 5.3epss 0.00

    In affected versions of Octopus Deploy it is possible to discover network details via error message

  • CVE-2023-2247MedMay 2, 2023
    risk 0.34cvss 5.3epss 0.00

    In affected versions of Octopus Deploy it is possible to unmask variable secrets using the variable preview function

  • CVE-2022-2507MedApr 19, 2023
    risk 0.34cvss 5.3epss 0.00

    In affected versions of Octopus Deploy it is possible to render user supplied input into the webpage

  • CVE-2022-2508MedOct 27, 2022
    risk 0.34cvss 5.3epss 0.01

    In affected versions of Octopus Server it is possible to reveal the existence of resources in a space that the user does not have access to due to verbose error messaging.

  • CVE-2022-2720MedOct 12, 2022
    risk 0.34cvss 5.3epss 0.00

    In affected versions of Octopus Server it was identified that when a sensitive value is a substring of another value, sensitive value masking will only partially work.

  • CVE-2022-2783MedOct 6, 2022
    risk 0.34cvss 5.3epss 0.00

    In affected versions of Octopus Server it was identified that a session cookie could be used as the CSRF token

  • CVE-2022-2781MedOct 6, 2022
    risk 0.34cvss 5.3epss 0.00

    In affected versions of Octopus Server it was identified that the same encryption process was used for both encrypting session cookies and variables.

  • CVE-2022-1901MedAug 19, 2022
    risk 0.34cvss 5.3epss 0.00

    In affected versions of Octopus Deploy it is possible to unmask sensitive variables by using variable preview.

  • CVE-2022-30532MedJul 19, 2022
    risk 0.34cvss 5.3epss 0.01

    In affected versions of Octopus Deploy, there is no logging of changes to artifacts within Octopus Deploy.

  • CVE-2022-1881MedJul 15, 2022
    risk 0.34cvss 5.3epss 0.01

    In affected versions of Octopus Server an Insecure Direct Object Reference vulnerability exists where it is possible for a user to download Project Exports from a Project they do not have permissions to access. This vulnerability only impacts projects within the same Space.

  • CVE-2019-19375MedNov 28, 2019
    risk 0.34cvss 5.3epss 0.00

    In Octopus Deploy before 2019.10.7, in a configuration where SSL offloading is enabled, the CSRF cookie was sometimes sent without the secure attribute. (The fix for this was backported to LTS versions 2019.6.14 and 2019.9.8.)

  • CVE-2025-0588MedFeb 11, 2025
    risk 0.32cvss 4.9epss 0.00

    In affected versions of Octopus Server it was possible for a user with sufficient access to set custom headers in all server responses. By submitting a specifically crafted referrer header the user could ensure that all subsequent server responses would return 500 errors…

  • CVE-2019-14525MedAug 5, 2019
    risk 0.32cvss 4.9epss 0.02

    In Octopus Deploy 2019.4.0 through 2019.6.x before 2019.6.6, and 2019.7.x before 2019.7.6, an authenticated system administrator is able to view sensitive values by visiting a server configuration page or making an API call.

  • CVE-2026-3237MedMar 17, 2026
    risk 0.28cvss 4.3epss 0.00

    In affected versions of Octopus Server it was possible for a low privileged user to manipulate an API request to change the signing key expiration and revocation time frames via an API endpoint that had incorrect permission validation. It was not possible to expose the signing…

  • CVE-2026-3236MedMar 5, 2026
    risk 0.28cvss 4.3epss 0.00

    In affected versions of Octopus Server it was possible to create a new API key from an existing access token resulting in the new API key having a lifetime exceeding the original API key used to mint the access token.

  • CVE-2023-4509MedApr 18, 2024
    risk 0.28cvss 4.3epss 0.00

    It is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt.

  • CVE-2022-2259MedMar 13, 2023
    risk 0.28cvss 4.3epss 0.00

    In affected versions of Octopus Deploy it is possible for a user to view Workerpools without being explicitly assigned permissions to view these items

  • CVE-2022-2258MedMar 13, 2023
    risk 0.28cvss 4.3epss 0.01

    In affected versions of Octopus Deploy it is possible for a user to view Tagsets without being explicitly assigned permissions to view these items

  • CVE-2022-2760MedSep 28, 2022
    risk 0.28cvss 4.3epss 0.00

    In affected versions of Octopus Deploy it is possible to reveal the Space ID of spaces that the user does not have access to view in an error message when a resource is part of another Space.

  • CVE-2022-1502MedMay 4, 2022
    risk 0.28cvss 4.3epss 0.01

    Permissions were not properly verified in the API on projects using version control in Git. This allowed projects to be modified by users with only ProjectView permissions.

  • CVE-2021-31818MedJun 17, 2021
    risk 0.28cvss 4.3epss 0.01

    Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API because user supplied data in the API request isn’t parameterised correctly. Exploiting this vulnerability could allow unauthorised access to database tables.

  • CVE-2020-16197MedAug 25, 2020
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Octopus Deploy 3.4. A deployment target can be configured with an Account or Certificate that is outside the scope of the deployment target. An authorised user can potentially use a certificate that they are not in scope to use. An authorised user is…

  • CVE-2020-12286MedApr 28, 2020
    risk 0.28cvss 4.3epss 0.01

    In Octopus Deploy before 2019.12.9 and 2020 before 2020.1.12, the TaskView permission is not scoped to any dimension. For example, a scoped user who is scoped to only one tenant can view server tasks scoped to any other tenant.

  • CVE-2019-19084MedNov 18, 2019
    risk 0.28cvss 4.3epss 0.01

    In Octopus Deploy 3.3.0 through 2019.10.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted package, triggering an exception that exposes underlying operating system details.

  • CVE-2019-15698MedAug 27, 2019
    risk 0.28cvss 4.3epss 0.01

    In Octopus Deploy 2019.7.3 through 2019.7.9, in certain circumstances, an authenticated user with VariableView permissions could view sensitive values. This is fixed in 2019.7.10.

  • CVE-2024-4456MedMay 8, 2024
    risk 0.27cvss 4.1epss 0.00

    In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting payload on the audit page.

  • CVE-2023-1904MedDec 14, 2023
    risk 0.27cvss 4.2epss 0.00

    In affected versions of Octopus Server it is possible for the OpenID client secret to be logged in clear text during the configuration of Octopus Server.

  • CVE-2024-4226LowApr 30, 2024
    risk 0.23cvss 3.5epss 0.00

    It was identified that in certain versions of Octopus Server, that a user created with no permissions could view all users, user roles and permissions. This functionality was removed in versions of Octopus Server after the fixed versions listed.