Known Vulnerabilities for products from Octopus
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Octopus".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-3237 json | In affected versions of Octopus Server it was possible for a low privileged user to manipulate an API request to change the s... | Not Provided | 2026-03-17 | 2026-04-07 |
| CVE-2023-2247 json | In affected versions of Octopus Deploy it is possible to unmask variable secrets using the variable preview function | 5.3 - MEDIUM | 2023-05-02 | 2023-12-14 |
| CVE-2023-1904 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.5 - HIGH | 2023-12-14 | 2023-12-19 |
| CVE-2022-30532 json | In affected versions of Octopus Deploy, there is no logging of changes to artifacts within Octopus Deploy. | 5.3 - MEDIUM | 2022-07-19 | 2022-08-18 |
| CVE-2022-29890 json | In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the su... | 6.1 - MEDIUM | 2022-07-15 | 2022-08-02 |
| CVE-2022-23184 json | In affected Octopus Server versions when the server HTTP and HTTPS bindings are configured to localhost, Octopus Server will ... | 6.1 - MEDIUM | 2022-02-07 | 2022-07-27 |
| CVE-2022-4898 json | In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the su... | 5.4 - MEDIUM | 2023-01-31 | 2023-02-21 |
| CVE-2022-4870 json | In affected versions of Octopus Deploy it is possible to discover network details via error message | 5.3 - MEDIUM | 2023-05-18 | 2023-05-25 |
| CVE-2022-4009 json | In affected versions of Octopus Deploy it is possible for a user to introduce code via offline package creation | 8.8 - HIGH | 2023-03-16 | 2023-08-08 |
| CVE-2022-4008 json | In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service | 5.5 - MEDIUM | 2023-05-10 | 2023-05-17 |
| CVE-2022-3614 json | In affected versions of Octopus Deploy users of certain browsers using AD to sign-in to Octopus Server were able to bypass au... | 6.1 - MEDIUM | 2023-01-03 | 2023-03-23 |
| CVE-2022-3460 json | In affected versions of Octopus Deploy it is possible for certain types of sensitive variables to inadvertently become unmask... | 7.5 - HIGH | 2023-01-03 | 2023-08-08 |
| CVE-2022-2883 json | In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service | 7.5 - HIGH | 2023-02-22 | 2023-03-03 |
| CVE-2022-2828 json | In affected versions of Octopus Server it is possible to reveal information about teams via the API due to an Insecure Direct... | 6.5 - MEDIUM | 2022-10-13 | 2022-10-14 |
| CVE-2022-2783 json | In affected versions of Octopus Server it was identified that a session cookie could be used as the CSRF token | 5.3 - MEDIUM | 2022-10-06 | 2023-08-08 |
| CVE-2022-2782 json | In affected versions of Octopus Server it is possible for a session token to be valid indefinitely due to improper validation... | 9.1 - CRITICAL | 2022-10-27 | 2022-10-28 |
| CVE-2022-2781 json | In affected versions of Octopus Server it was identified that the same encryption process was used for both encrypting sessio... | 5.3 - MEDIUM | 2022-10-06 | 2023-08-08 |
| CVE-2022-2780 json | In affected versions of Octopus Server it is possible to use the Git Connectivity test function on the VCS project to initiat... | 8.1 - HIGH | 2022-10-14 | 2022-10-19 |
| CVE-2022-2778 json | In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes. | 9.8 - CRITICAL | 2022-09-30 | 2023-08-08 |
| CVE-2022-2760 json | In affected versions of Octopus Deploy it is possible to reveal the Space ID of spaces that the user does not have access to ... | 4.3 - MEDIUM | 2022-09-28 | 2022-09-29 |
Known software with vulnerabilities from Octopus
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Octopus | Octopusdsc | 2.0.103 |
| Application | Octopus | Octopus Deploy | 0.9 |
| Application | Octopus | Server | - |