In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes.
In affected versions of Octopus Deploy it is possible to upload a package to built-in feed with insufficient permissions after re-indexing packages.
In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service via the package upload function.
In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service using the Variable Project Template.
In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service targeting the build information request validation.
In affected versions of Octopus Deploy it is possible to unmask sensitive variables by using variable preview.
In affected versions of Octopus Deploy, there is no logging of changes to artifacts within Octopus Deploy.
In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the support link.
In affected versions of Octopus Server an Insecure Direct Object Reference vulnerability exists where it is possible for a user to download Project E…
In Octopus Server after version 2022.1.1495 and before 2022.1.2647 if private spaces were enabled via the experimental feature flag all new users wou…
When generating a user invitation code in Octopus Server, the validity of this code can be set for a specific number of users. It was possible to byp…
In affected Octopus Server versions when the server HTTP and HTTPS bindings are configured to localhost, Octopus Server will allow open redirects.
When the Windows Tentacle docker image starts up it logs all the commands that it runs along with the arguments, which writes the Octopus Server API …
When Octopus Tentacle is installed on a Linux operating system, the systemd service file permissions are misconfigured. This could lead to a local un…
When Octopus Server is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL s…
When Octopus Tentacle is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL…
In Halibut versions prior to 4.4.7 there is a deserialisation vulnerability that could allow remote code execution on systems that already trust each…
In Octopus Server after version 2018.8.2 if the Octopus Server Web Request Proxy is configured with authentication, the password is shown in plaintex…
When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the O…
When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the O…
Cleartext storage of sensitive information in multiple versions of Octopus Server where in certain situations when running import or export processes…
OctopusDSC is a PowerShell module with DSC resources that can be used to install and configure an Octopus Deploy Server and Tentacle agent. In Octopu…
In Octopus Deploy through 2020.4.2, an attacker could redirect users to an external site via a modified HTTP Host header.
An issue was discovered in Octopus Deploy through 2020.4.4. If enabled, the websocket endpoint may allow an untrusted tentacle host to present itself…
In Octopus Deploy 3.1.0 to 2020.4.0, certain scripts can reveal sensitive information to the user in the task logs.
In Octopus Deploy 2020.3.x before 2020.3.4 and 2020.4.x before 2020.4.1, if an authenticated user creates a deployment or runbook process using Azure…
In Octopus Deploy 2018.8.0 through 2019.x before 2019.12.2, an authenticated user with could trigger a deployment that leaks the Helm Chart repositor…
In Octopus Deploy before 2020.1.5, for customers running on-premises Active Directory linked to their Octopus server, an authenticated user can lever…
In Octopus Deploy before 2019.10.6, an authenticated user with TeamEdit permission could send a malformed Team API request that bypasses input valida…
In Octopus Deploy before 2019.10.7, in a configuration where SSL offloading is enabled, the CSRF cookie was sometimes sent without the secure attribu…