Vendor CVEs
Octopus
All CVEs
105 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-1656 | Low | 0.17 | 2.6 | 0.00 | Sep 11, 2024 | Affected versions of Octopus Server had a weak content security policy. | ||
| CVE-2024-7998 | Low | 0.17 | 2.6 | 0.00 | Aug 21, 2024 | In affected versions of Octopus Server OIDC cookies were using the wrong expiration time which could result in them using the maximum lifespan. | ||
| CVE-2024-4811 | Low | 0.14 | 2.2 | 0.00 | Jul 25, 2024 | In affected versions of Octopus Server under certain conditions, a user with specific role assignments can access restricted project artifacts. | ||
| CVE-2026-12702 | Med | 0.00 | — | 0.00 | Jul 24, 2026 | In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment. | ||
| CVE-2021-21270 | Med | 0.00 | 6.2 | 0.00 | Jan 22, 2021 | OctopusDSC is a PowerShell module with DSC resources that can be used to install and configure an Octopus Deploy Server and Tentacle agent. In OctopusDSC version 4.0.977 and earlier a customer API key used to connect to Octopus Server is exposed via logging in plaintext. This… |
- risk 0.17cvss 2.6epss 0.00
Affected versions of Octopus Server had a weak content security policy.
- risk 0.17cvss 2.6epss 0.00
In affected versions of Octopus Server OIDC cookies were using the wrong expiration time which could result in them using the maximum lifespan.
- risk 0.14cvss 2.2epss 0.00
In affected versions of Octopus Server under certain conditions, a user with specific role assignments can access restricted project artifacts.
- risk 0.00cvss —epss 0.00
In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment.
- risk 0.00cvss 6.2epss 0.00
OctopusDSC is a PowerShell module with DSC resources that can be used to install and configure an Octopus Deploy Server and Tentacle agent. In OctopusDSC version 4.0.977 and earlier a customer API key used to connect to Octopus Server is exposed via logging in plaintext. This…
Page 3 of 3