Vulnerability index

Browse CVEs

82 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Octopus Server CRITICAL 9.8
CVE-2022-2778

In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes.

Fix: 2022.2.8277 / 2022.3.10405+
Fix from $2,300 2022-09-30
Octopus Server MEDIUM 6.5
CVE-2022-2528

In affected versions of Octopus Deploy it is possible to upload a package to built-in feed with insufficient permissions after re-indexing packages.

Fix: 2022.1.3106 / 2022.2.7718+
Fix from $1,600 2022-09-09
Octopus Server HIGH 7.5
CVE-2022-2049

In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service via the package upload function.

Fix: 2022.1.2894 / 2022.2.6872+
Fix from $1,950 2022-08-19
Octopus Server HIGH 7.5
CVE-2022-2074

In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service using the Variable Project Template.

Fix: 2022.1.2894 / 2022.2.6872+
Fix from $1,950 2022-08-19
Octopus Server HIGH 7.5
CVE-2022-2075

In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service targeting the build information request validation.

Fix: 2022.1.2894 / 2022.2.6872+
Fix from $1,950 2022-08-19
Octopus Server MEDIUM 5.3
CVE-2022-1901

In affected versions of Octopus Deploy it is possible to unmask sensitive variables by using variable preview.

Fix: 2022.1.3009 / 2022.2.7244+
Fix from $1,600 2022-08-19
Octopus Server MEDIUM 5.3
CVE-2022-30532

In affected versions of Octopus Deploy, there is no logging of changes to artifacts within Octopus Deploy.

Fix: 2021.3.13021 / 2022.1.2849+
Fix from $1,600 2022-07-19
Octopus Server MEDIUM 6.1
CVE-2022-29890

In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the support link.

Fix: 2021.3.13021 / 2022.1.2849+
Fix from $1,600 2022-07-15
Octopus Server MEDIUM 5.3
CVE-2022-1881

In affected versions of Octopus Server an Insecure Direct Object Reference vulnerability exists where it is possible for a user to download Project E…

Fix: 2021.3.13021 / 2022.1.2894+
Fix from $1,600 2022-07-15
Octopus Deploy HIGH 7.5
CVE-2022-2013

In Octopus Server after version 2022.1.1495 and before 2022.1.2647 if private spaces were enabled via the experimental feature flag all new users wou…

Fix: 2022.1.2647+
Fix from $1,950 2022-06-13
Octopus Server HIGH 7.5
CVE-2022-1670

When generating a user invitation code in Octopus Server, the validity of this code can be set for a specific number of users. It was possible to byp…

Fix: 2021.3.12533 / 2022.1.53+
Fix from $1,950 2022-05-19
Octopus Deploy MEDIUM 6.1
CVE-2022-23184

In affected Octopus Server versions when the server HTTP and HTTPS bindings are configured to localhost, Octopus Server will allow open redirects.

Fix: 2021.2.8011 / 2021.3.11057+
Fix from $1,600 2022-02-07
Tentacle MEDIUM 5.5
CVE-2021-31821

When the Windows Tentacle docker image starts up it logs all the commands that it runs along with the arguments, which writes the Octopus Server API …

Fix: 6.1.1266+
Fix from $1,600 2022-01-19
Tentacle HIGH 7.8
CVE-2021-31822

When Octopus Tentacle is installed on a Linux operating system, the systemd service file permissions are misconfigured. This could lead to a local un…

Fix: 6.1.1116+
Fix from $1,950 2021-11-24
Octopus Deploy HIGH 7.8
CVE-2021-26556

When Octopus Server is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL s…

Fix: 2020.4.229 / 2020.5.256+
Fix from $1,950 2021-10-07
Tentacle HIGH 7.8
CVE-2021-26557

When Octopus Tentacle is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL…

Fix: 6.0.489+
Fix from $1,950 2021-10-07
Halibut CRITICAL 9.8
CVE-2021-31819

In Halibut versions prior to 4.4.7 there is a deserialisation vulnerability that could allow remote code execution on systems that already trust each…

Fix: 4.4.7+
Fix from $2,300 2021-09-22
Octopus Server HIGH 7.5
CVE-2021-31820

In Octopus Server after version 2018.8.2 if the Octopus Server Web Request Proxy is configured with authentication, the password is shown in plaintex…

Fix: 2020.6.5310 / 2021.1.7622+
Fix from $1,950 2021-08-18
Server HIGH 7.5
CVE-2021-31816

When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the O…

Fix: 2020.6.5146 / 2021.1.7316+
Fix from $1,950 2021-07-08
Server HIGH 7.5
CVE-2021-31817

When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the O…

Fix: 2020.6.5146 / 2021.1.7316+
Fix from $1,950 2021-07-08
Server HIGH 7.5
CVE-2021-30183

Cleartext storage of sensitive information in multiple versions of Octopus Server where in certain situations when running import or export processes…

Fix: 2020.5.329 / 2020.6.4847+
Fix from $1,950 2021-05-14
Octopusdsc MEDIUM 5.5
CVE-2021-21270

OctopusDSC is a PowerShell module with DSC resources that can be used to install and configure an Octopus Deploy Server and Tentacle agent. In Octopu…

Fix: 4.0.1002+
Fix from $1,600 2021-01-22
Octopus Deploy MEDIUM 6.1
CVE-2020-26161

In Octopus Deploy through 2020.4.2, an attacker could redirect users to an external site via a modified HTTP Host header.

Fix: after 2020.4.2
Fix from $1,600 2020-10-26
Octopus Deploy HIGH 7.5
CVE-2020-27155

An issue was discovered in Octopus Deploy through 2020.4.4. If enabled, the websocket endpoint may allow an untrusted tentacle host to present itself…

Fix: after 2020.4.4
Fix from $1,950 2020-10-22
Octopus Deploy HIGH 7.5
CVE-2020-25825

In Octopus Deploy 3.1.0 to 2020.4.0, certain scripts can reveal sensitive information to the user in the task logs.

Fix: after 2020.4.0
Fix from $1,950 2020-10-12
Octopus Deploy HIGH 7.5
CVE-2020-24566

In Octopus Deploy 2020.3.x before 2020.3.4 and 2020.4.x before 2020.4.1, if an authenticated user creates a deployment or runbook process using Azure…

Fix: 2020.3.4+
Fix from $1,950 2020-09-09
Octopus Deploy MEDIUM 6.5
CVE-2020-14470

In Octopus Deploy 2018.8.0 through 2019.x before 2019.12.2, an authenticated user with could trigger a deployment that leaks the Helm Chart repositor…

Fix: 2019.12.2+
Fix from $1,600 2020-06-19
Octopus Deploy HIGH 8.8
CVE-2020-10678

In Octopus Deploy before 2020.1.5, for customers running on-premises Active Directory linked to their Octopus server, an authenticated user can lever…

Fix: 2020.1.5+
Fix from $1,950 2020-03-19
Octopus Deploy MEDIUM 6.5
CVE-2019-19376

In Octopus Deploy before 2019.10.6, an authenticated user with TeamEdit permission could send a malformed Team API request that bypasses input valida…

Fix: 2019.6.14 / 2019.9.8+
Fix from $1,600 2019-11-28
Octopus Deploy MEDIUM 5.3
CVE-2019-19375

In Octopus Deploy before 2019.10.7, in a configuration where SSL offloading is enabled, the CSRF cookie was sometimes sent without the secure attribu…

Fix: 2019.6.14 / 2019.9.8+
Fix from $1,600 2019-11-28