Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Octopus_server
(Octopus)| Repositories |
Unknown: This might be proprietary software. |
| #Vulnerabilities | 60 |
| Date | Id | Summary | Products | Score | Patch | Annotated |
|---|---|---|---|---|---|---|
| 2022-08-19 | CVE-2022-2049 | In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service via the package upload function. | Octopus_server | 7.5 | ||
| 2022-08-19 | CVE-2022-2075 | In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service targeting the build information request validation. | Octopus_server | 7.5 | ||
| 2022-09-09 | CVE-2022-2528 | In affected versions of Octopus Deploy it is possible to upload a package to built-in feed with insufficient permissions after re-indexing packages. | Octopus_server | 6.5 | ||
| 2022-10-06 | CVE-2022-2781 | In affected versions of Octopus Server it was identified that the same encryption process was used for both encrypting session cookies and variables. | Octopus_server | 5.3 | ||
| 2022-10-06 | CVE-2022-2783 | In affected versions of Octopus Server it was identified that a session cookie could be used as the CSRF token | Octopus_server | 5.3 | ||
| 2022-11-25 | CVE-2022-2721 | In affected versions of Octopus Server it is possible for target discovery to print certain values marked as sensitive to log files in plaint-text in when verbose logging is enabled. | Octopus_server | 7.5 | ||
| 2023-01-03 | CVE-2022-3460 | In affected versions of Octopus Deploy it is possible for certain types of sensitive variables to inadvertently become unmasked when viewed in variable preview. | Octopus_server | 7.5 | ||
| 2023-01-03 | CVE-2022-3614 | In affected versions of Octopus Deploy users of certain browsers using AD to sign-in to Octopus Server were able to bypass authentication checks and be redirected to the configured redirect url without any validation. | Octopus_server | 6.1 | ||
| 2023-01-31 | CVE-2022-4898 | In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the support link. This was initially resolved in advisory 2022-07 however it was identified that the fix could be bypassed in certain circumstances. A different approach was taken to prevent the possibility of the support link being susceptible to XSS | Octopus_server | 5.4 | ||
| 2023-08-02 | CVE-2022-2346 | In affected versions of Octopus Deploy it is possible for a low privileged guest user to interact with extension endpoints. | Octopus_server | 4.3 |