Vulnerability index

Browse CVEs

82 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Server MEDIUM 5.4
CVE-2019-19085

A persistent cross-site scripting (XSS) vulnerability in Octopus Server 3.4.0 through 2019.10.5 allows remote authenticated attackers to inject arbit…

Fix: after 2019.10.5
Fix from $1,600 2019-11-18
Server MEDIUM 6.5
CVE-2019-15507

In Octopus Deploy versions 2018.8.4 to 2019.7.6, when a web request proxy is configured, an authenticated user (in certain limited special-characters…

Fix: after 2019.7.6
Fix from $1,600 2019-08-23
Server MEDIUM 6.5
CVE-2019-15508

In Octopus Tentacle versions 3.0.8 to 5.0.0, when a web request proxy is configured, an authenticated user (in certain limited OctopusPrintVariables …

Fix: after 2019.7.6
Fix from $1,600 2019-08-23
Octopus Deploy MEDIUM 6.5
CVE-2019-14268

In Octopus Deploy versions 3.0.19 to 2019.7.2, when a web request proxy is configured, an authenticated user (in certain limited circumstances) could…

Fix: after 2019.7.2
Fix from $1,600 2019-07-25
Octopus Deploy HIGH 8.1
CVE-2019-11632

In Octopus Deploy 2019.1.0 through 2019.3.1 and 2019.4.0 through 2019.4.5, an authenticated user with the VariableViewUnscoped or VariableEditUnscope…

Fix: after 2019.4.5
Fix from $1,950 2019-05-01
Octopus Deploy MEDIUM 6.5
CVE-2019-8944

An Information Exposure issue in the Terraform deployment step in Octopus Deploy before 2019.1.8 (and before 2018.10.4 LTS) allows remote authenticat…

Fix: 2019.1.8+
Fix from $1,600 2019-02-20
Octopus Server HIGH 8.8
CVE-2018-18850EPSS 12%

In Octopus Deploy 2018.8.0 through 2018.9.x before 2018.9.1, an authenticated user with permission to modify deployment processes could upload a mali…

Fix: 2018.9.1+
Fix from $1,950 2018-10-31
Octopus Deploy MEDIUM 6.5
CVE-2018-12884

In Octopus Deploy 3.0 onwards (before 2018.6.7), an authenticated user with incorrect permissions may be able to create Accounts under the Infrastruc…

Mitigation only
Fix from $1,600 2018-06-26
Octopus Server HIGH 7.5
CVE-2018-12089

In Octopus Deploy version 2018.5.1 to 2018.5.7, a user with Task View is able to view a password for a Service Fabric Cluster, when the Service Fabri…

Fix: after 2018.5.7
Fix from $1,950 2018-06-11
Octopus Server CRITICAL 9.8
CVE-2018-11320

In Octopus Deploy 2018.4.4 through 2018.5.1, Octopus variables that are sourced from the target do not have sensitive values obfuscated in the deploy…

Fix: after 2018.5.1
Fix from $2,300 2018-05-21
Octopus Deploy MEDIUM 5.4
CVE-2018-10581

In Octopus Deploy 3.4.x before 2018.4.7, an authenticated user is able to view/update/save variable values within the Tenant Variables area for Envir…

Fix: 2018.4.7+
Fix from $1,600 2018-05-01
Octopus Deploy HIGH 7.5
CVE-2018-10550

In Octopus Deploy before 2018.4.7, target and tenant tag variable scopes were not checked against the list of tenants the user has access to.

Fix: 2018.4.7+
Fix from $1,950 2018-04-30
Octopus Deploy MEDIUM 6.5
CVE-2018-9039

In Octopus Deploy 2.0 and later before 2018.3.7, an authenticated user, with variable edit permissions, can scope some variables to targets greater t…

Fix: 2018.3.7+
Fix from $1,600 2018-03-27
Octopus Deploy HIGH 8.8
CVE-2018-5706

An issue was discovered in Octopus Deploy before 4.1.9. Any user with user editing permissions can modify teams to give themselves Administer System …

Fix: 4.1.9+
Fix from $1,950 2018-01-16
Octopus Deploy HIGH 8.8
CVE-2018-4862

In Octopus Deploy versions 3.2.11 - 4.1.5 (fixed in 4.1.6), an authenticated user with ProcessEdit permission could reference an Azure account in suc…

Fix: after 4.1.5
Fix from $1,950 2018-01-03
Octopus Deploy HIGH 8.8
CVE-2017-17665

In Octopus Deploy before 4.1.3, the machine update process doesn't check that the user has access to all environments. This allows an access-control …

Fix: 4.1.3+
Fix from $1,950 2017-12-13
Octopus Deploy MEDIUM 5.4
CVE-2017-16810

Cross-site scripting (XSS) vulnerability in the All Variables tab in Octopus Deploy 3.4.0-3.13.6 (fixed in 3.13.7) allows remote attackers to inject …

Fix: after 3.13.6
Fix from $1,600 2017-11-14
Octopus Deploy MEDIUM 5.4
CVE-2017-16801

Cross-site scripting (XSS) vulnerability in Octopus Deploy 3.7.0-3.17.13 (fixed in 3.17.14) allows remote authenticated users to inject arbitrary web…

Fix: after 3.17.3
Fix from $1,600 2017-11-13
Octopus Deploy HIGH 7.5
CVE-2017-15609

Octopus before 3.17.7 allows attackers to obtain sensitive cleartext information by reading a variable JSON file in certain situations involving Offl…

Fix: after 3.17.6
Fix from $1,950 2017-10-19
Octopus Deploy MEDIUM 6.5
CVE-2017-15610

An issue was discovered in Octopus before 3.17.7. When the special Guest user account is granted the CertificateExportPrivateKey permission, and Gues…

Fix: after 3.17.6
Fix from $1,600 2017-10-19
Octopus Deploy MEDIUM 6.5
CVE-2017-15611

In Octopus before 3.17.7, an authenticated user who was explicitly granted the permission to invite new users (aka UserInvite) can invite users to te…

Fix: after 3.17.6
Fix from $1,600 2017-10-19
Octopus Deploy MEDIUM 5.7
CVE-2017-11348

In Octopus Deploy 3.x before 3.15.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted NuGet pa…

Mitigation only
Fix from $1,600 2017-07-17