VYPR

Vendor CVEs

Octopus

All CVEs

105 total · sorted by risk
  • CVE-2024-1656LowSep 11, 2024
    risk 0.17cvss 2.6epss 0.00

    Affected versions of Octopus Server had a weak content security policy.

  • CVE-2024-7998LowAug 21, 2024
    risk 0.17cvss 2.6epss 0.00

    In affected versions of Octopus Server OIDC cookies were using the wrong expiration time which could result in them using the maximum lifespan.

  • CVE-2024-4811LowJul 25, 2024
    risk 0.14cvss 2.2epss 0.00

    In affected versions of Octopus Server under certain conditions, a user with specific role assignments can access restricted project artifacts.

  • CVE-2026-12702MedJul 24, 2026
    risk 0.00cvss epss 0.00

    In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment.

  • CVE-2021-21270MedJan 22, 2021
    risk 0.00cvss 6.2epss 0.00

    OctopusDSC is a PowerShell module with DSC resources that can be used to install and configure an Octopus Deploy Server and Tentacle agent. In OctopusDSC version 4.0.977 and earlier a customer API key used to connect to Octopus Server is exposed via logging in plaintext. This…

Page 3 of 3