VYPR

Vendor CVEs

Octopus

All CVEs

106 total · sorted by risk
  • CVE-2019-15507Aug 23, 2019
    risk 0.00cvss epss 0.01

    In Octopus Deploy versions 2018.8.4 to 2019.7.6, when a web request proxy is configured, an authenticated user (in certain limited special-characters circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is…

  • CVE-2019-15508Aug 23, 2019
    risk 0.00cvss epss 0.01

    In Octopus Tentacle versions 3.0.8 to 5.0.0, when a web request proxy is configured, an authenticated user (in certain limited OctopusPrintVariables circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is…

  • CVE-2019-14525Aug 5, 2019
    risk 0.00cvss epss 0.02

    In Octopus Deploy 2019.4.0 through 2019.6.x before 2019.6.6, and 2019.7.x before 2019.7.6, an authenticated system administrator is able to view sensitive values by visiting a server configuration page or making an API call.

  • CVE-2019-14268Jul 25, 2019
    risk 0.00cvss epss 0.01

    In Octopus Deploy versions 3.0.19 to 2019.7.2, when a web request proxy is configured, an authenticated user (in certain limited circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is fixed in 2019.7.3.…

  • CVE-2019-11632May 1, 2019
    risk 0.00cvss epss 0.01

    In Octopus Deploy 2019.1.0 through 2019.3.1 and 2019.4.0 through 2019.4.5, an authenticated user with the VariableViewUnscoped or VariableEditUnscoped permission scoped to a specific project could view or edit unscoped variables from a different project. (These permissions are…

  • CVE-2019-8944Feb 20, 2019
    risk 0.00cvss epss 0.02

    An Information Exposure issue in the Terraform deployment step in Octopus Deploy before 2019.1.8 (and before 2018.10.4 LTS) allows remote authenticated users to view sensitive Terraform output variables via log files.

Page 3 of 3