VYPR

Vendor CVEs

Octopus

All CVEs

108 total · sorted by risk
  • CVE-2019-15698MedAug 27, 2019
    risk 0.28cvss 4.3epss 0.01

    In Octopus Deploy 2019.7.3 through 2019.7.9, in certain circumstances, an authenticated user with VariableView permissions could view sensitive values. This is fixed in 2019.7.10.

  • CVE-2024-4456MedMay 8, 2024
    risk 0.27cvss 4.1epss 0.00

    In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting payload on the audit page.

  • CVE-2023-1904MedDec 14, 2023
    risk 0.27cvss 4.2epss 0.00

    In affected versions of Octopus Server it is possible for the OpenID client secret to be logged in clear text during the configuration of Octopus Server.

  • CVE-2024-4226LowApr 30, 2024
    risk 0.23cvss 3.5epss 0.00

    It was identified that in certain versions of Octopus Server, that a user created with no permissions could view all users, user roles and permissions. This functionality was removed in versions of Octopus Server after the fixed versions listed.

  • CVE-2024-1656LowSep 11, 2024
    risk 0.17cvss 2.6epss 0.00

    Affected versions of Octopus Server had a weak content security policy.

  • CVE-2024-7998LowAug 21, 2024
    risk 0.17cvss 2.6epss 0.00

    In affected versions of Octopus Server OIDC cookies were using the wrong expiration time which could result in them using the maximum lifespan.

  • CVE-2024-4811LowJul 25, 2024
    risk 0.14cvss 2.2epss 0.00

    In affected versions of Octopus Server under certain conditions, a user with specific role assignments can access restricted project artifacts.

  • CVE-2021-21270MedJan 22, 2021
    risk 0.00cvss 6.2epss 0.00

    OctopusDSC is a PowerShell module with DSC resources that can be used to install and configure an Octopus Deploy Server and Tentacle agent. In OctopusDSC version 4.0.977 and earlier a customer API key used to connect to Octopus Server is exposed via logging in plaintext. This…

Page 3 of 3