Vendor CVEs
Octopus
All CVEs
108 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-15698 | Med | 0.28 | 4.3 | 0.01 | Aug 27, 2019 | In Octopus Deploy 2019.7.3 through 2019.7.9, in certain circumstances, an authenticated user with VariableView permissions could view sensitive values. This is fixed in 2019.7.10. | ||
| CVE-2024-4456 | Med | 0.27 | 4.1 | 0.00 | May 8, 2024 | In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting payload on the audit page. | ||
| CVE-2023-1904 | Med | 0.27 | 4.2 | 0.00 | Dec 14, 2023 | In affected versions of Octopus Server it is possible for the OpenID client secret to be logged in clear text during the configuration of Octopus Server. | ||
| CVE-2024-4226 | Low | 0.23 | 3.5 | 0.00 | Apr 30, 2024 | It was identified that in certain versions of Octopus Server, that a user created with no permissions could view all users, user roles and permissions. This functionality was removed in versions of Octopus Server after the fixed versions listed. | ||
| CVE-2024-1656 | Low | 0.17 | 2.6 | 0.00 | Sep 11, 2024 | Affected versions of Octopus Server had a weak content security policy. | ||
| CVE-2024-7998 | Low | 0.17 | 2.6 | 0.00 | Aug 21, 2024 | In affected versions of Octopus Server OIDC cookies were using the wrong expiration time which could result in them using the maximum lifespan. | ||
| CVE-2024-4811 | Low | 0.14 | 2.2 | 0.00 | Jul 25, 2024 | In affected versions of Octopus Server under certain conditions, a user with specific role assignments can access restricted project artifacts. | ||
| CVE-2021-21270 | Med | 0.00 | 6.2 | 0.00 | Jan 22, 2021 | OctopusDSC is a PowerShell module with DSC resources that can be used to install and configure an Octopus Deploy Server and Tentacle agent. In OctopusDSC version 4.0.977 and earlier a customer API key used to connect to Octopus Server is exposed via logging in plaintext. This… |
- risk 0.28cvss 4.3epss 0.01
In Octopus Deploy 2019.7.3 through 2019.7.9, in certain circumstances, an authenticated user with VariableView permissions could view sensitive values. This is fixed in 2019.7.10.
- risk 0.27cvss 4.1epss 0.00
In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting payload on the audit page.
- risk 0.27cvss 4.2epss 0.00
In affected versions of Octopus Server it is possible for the OpenID client secret to be logged in clear text during the configuration of Octopus Server.
- risk 0.23cvss 3.5epss 0.00
It was identified that in certain versions of Octopus Server, that a user created with no permissions could view all users, user roles and permissions. This functionality was removed in versions of Octopus Server after the fixed versions listed.
- risk 0.17cvss 2.6epss 0.00
Affected versions of Octopus Server had a weak content security policy.
- risk 0.17cvss 2.6epss 0.00
In affected versions of Octopus Server OIDC cookies were using the wrong expiration time which could result in them using the maximum lifespan.
- risk 0.14cvss 2.2epss 0.00
In affected versions of Octopus Server under certain conditions, a user with specific role assignments can access restricted project artifacts.
- risk 0.00cvss 6.2epss 0.00
OctopusDSC is a PowerShell module with DSC resources that can be used to install and configure an Octopus Deploy Server and Tentacle agent. In OctopusDSC version 4.0.977 and earlier a customer API key used to connect to Octopus Server is exposed via logging in plaintext. This…
Page 3 of 3