Known Vulnerabilities for products from Octopus

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Octopus".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-3237 json In affected versions of Octopus Server it was possible for a low privileged user to manipulate an API request to change the s... Not Provided 2026-03-17 2026-04-07
CVE-2023-2247 json In affected versions of Octopus Deploy it is possible to unmask variable secrets using the variable preview function 5.3 - MEDIUM 2023-05-02 2023-12-14
CVE-2023-1904 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 7.5 - HIGH 2023-12-14 2023-12-19
CVE-2022-30532 json In affected versions of Octopus Deploy, there is no logging of changes to artifacts within Octopus Deploy. 5.3 - MEDIUM 2022-07-19 2022-08-18
CVE-2022-29890 json In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the su... 6.1 - MEDIUM 2022-07-15 2022-08-02
CVE-2022-23184 json In affected Octopus Server versions when the server HTTP and HTTPS bindings are configured to localhost, Octopus Server will ... 6.1 - MEDIUM 2022-02-07 2022-07-27
CVE-2022-4898 json In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the su... 5.4 - MEDIUM 2023-01-31 2023-02-21
CVE-2022-4870 json In affected versions of Octopus Deploy it is possible to discover network details via error message 5.3 - MEDIUM 2023-05-18 2023-05-25
CVE-2022-4009 json In affected versions of Octopus Deploy it is possible for a user to introduce code via offline package creation 8.8 - HIGH 2023-03-16 2023-08-08
CVE-2022-4008 json In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service 5.5 - MEDIUM 2023-05-10 2023-05-17
CVE-2022-3614 json In affected versions of Octopus Deploy users of certain browsers using AD to sign-in to Octopus Server were able to bypass au... 6.1 - MEDIUM 2023-01-03 2023-03-23
CVE-2022-3460 json In affected versions of Octopus Deploy it is possible for certain types of sensitive variables to inadvertently become unmask... 7.5 - HIGH 2023-01-03 2023-08-08
CVE-2022-2883 json In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service 7.5 - HIGH 2023-02-22 2023-03-03
CVE-2022-2828 json In affected versions of Octopus Server it is possible to reveal information about teams via the API due to an Insecure Direct... 6.5 - MEDIUM 2022-10-13 2022-10-14
CVE-2022-2783 json In affected versions of Octopus Server it was identified that a session cookie could be used as the CSRF token 5.3 - MEDIUM 2022-10-06 2023-08-08
CVE-2022-2782 json In affected versions of Octopus Server it is possible for a session token to be valid indefinitely due to improper validation... 9.1 - CRITICAL 2022-10-27 2022-10-28
CVE-2022-2781 json In affected versions of Octopus Server it was identified that the same encryption process was used for both encrypting sessio... 5.3 - MEDIUM 2022-10-06 2023-08-08
CVE-2022-2780 json In affected versions of Octopus Server it is possible to use the Git Connectivity test function on the VCS project to initiat... 8.1 - HIGH 2022-10-14 2022-10-19
CVE-2022-2778 json In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes. 9.8 - CRITICAL 2022-09-30 2023-08-08
CVE-2022-2760 json In affected versions of Octopus Deploy it is possible to reveal the Space ID of spaces that the user does not have access to ... 4.3 - MEDIUM 2022-09-28 2022-09-29

Known software with vulnerabilities from Octopus

Type Vendor Product Version
ApplicationOctopusOctopusdsc2.0.103
ApplicationOctopusOctopus Deploy0.9
ApplicationOctopusServer-