Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2022-2778
In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes.
Octopus Server
2022.2.8277 / 2022.3.10405+
MEDIUM 6.5
CVE-2022-2528
In affected versions of Octopus Deploy it is possible to upload a package to built-in feed with insufficient permissions after re-indexing packages.
Octopus Server
2022.1.3106 / 2022.2.7718+
HIGH 7.5
CVE-2022-2049
In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service via the package upload function.
Octopus Server
2022.1.2894 / 2022.2.6872+
HIGH 7.5
CVE-2022-2074
In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service using the Variable Project Template.
Octopus Server
2022.1.2894 / 2022.2.6872+
HIGH 7.5
CVE-2022-2075
In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service targeting the build information request validation.
Octopus Server
2022.1.2894 / 2022.2.6872+
MEDIUM 5.3
CVE-2022-1901
In affected versions of Octopus Deploy it is possible to unmask sensitive variables by using variable preview.
Octopus Server
2022.1.3009 / 2022.2.7244+
MEDIUM 5.3
CVE-2022-30532
In affected versions of Octopus Deploy, there is no logging of changes to artifacts within Octopus Deploy.
Octopus Server
2021.3.13021 / 2022.1.2849+
MEDIUM 6.1
CVE-2022-29890
In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the support link.
Octopus Server
2021.3.13021 / 2022.1.2849+
MEDIUM 5.3
CVE-2022-1881
In affected versions of Octopus Server an Insecure Direct Object Reference vulnerability exists where it is possible for a user to download Project E…
Octopus Server
2021.3.13021 / 2022.1.2894+
HIGH 7.5
CVE-2022-2013
In Octopus Server after version 2022.1.1495 and before 2022.1.2647 if private spaces were enabled via the experimental feature flag all new users wou…
Octopus Deploy
2022.1.2647+
HIGH 7.5
CVE-2022-1670
When generating a user invitation code in Octopus Server, the validity of this code can be set for a specific number of users. It was possible to byp…
Octopus Server
2021.3.12533 / 2022.1.53+
MEDIUM 6.1
CVE-2022-23184
In affected Octopus Server versions when the server HTTP and HTTPS bindings are configured to localhost, Octopus Server will allow open redirects.
Octopus Deploy
2021.2.8011 / 2021.3.11057+
MEDIUM 5.5
CVE-2021-31821
When the Windows Tentacle docker image starts up it logs all the commands that it runs along with the arguments, which writes the Octopus Server API …
Tentacle
6.1.1266+
HIGH 7.8
CVE-2021-31822
When Octopus Tentacle is installed on a Linux operating system, the systemd service file permissions are misconfigured. This could lead to a local un…
Tentacle
6.1.1116+
HIGH 7.8
CVE-2021-26556
When Octopus Server is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL s…
Octopus Deploy
2020.4.229 / 2020.5.256+
HIGH 7.8
CVE-2021-26557
When Octopus Tentacle is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL…
Tentacle
6.0.489+
CRITICAL 9.8
CVE-2021-31819
In Halibut versions prior to 4.4.7 there is a deserialisation vulnerability that could allow remote code execution on systems that already trust each…
Halibut
4.4.7+
HIGH 7.5
CVE-2021-31820
In Octopus Server after version 2018.8.2 if the Octopus Server Web Request Proxy is configured with authentication, the password is shown in plaintex…
Octopus Server
2020.6.5310 / 2021.1.7622+
HIGH 7.5
CVE-2021-31816
When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the O…
Server
2020.6.5146 / 2021.1.7316+
HIGH 7.5
CVE-2021-31817
When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the O…
Server
2020.6.5146 / 2021.1.7316+
HIGH 7.5
CVE-2021-30183
Cleartext storage of sensitive information in multiple versions of Octopus Server where in certain situations when running import or export processes…
Server
2020.5.329 / 2020.6.4847+
MEDIUM 5.5
CVE-2021-21270
OctopusDSC is a PowerShell module with DSC resources that can be used to install and configure an Octopus Deploy Server and Tentacle agent. In Octopu…
Octopusdsc
4.0.1002+
MEDIUM 6.1
CVE-2020-26161
In Octopus Deploy through 2020.4.2, an attacker could redirect users to an external site via a modified HTTP Host header.
Octopus Deploy
after 2020.4.2
HIGH 7.5
CVE-2020-27155
An issue was discovered in Octopus Deploy through 2020.4.4. If enabled, the websocket endpoint may allow an untrusted tentacle host to present itself…
Octopus Deploy
after 2020.4.4
HIGH 7.5
CVE-2020-25825
In Octopus Deploy 3.1.0 to 2020.4.0, certain scripts can reveal sensitive information to the user in the task logs.
Octopus Deploy
after 2020.4.0
HIGH 7.5
CVE-2020-24566
In Octopus Deploy 2020.3.x before 2020.3.4 and 2020.4.x before 2020.4.1, if an authenticated user creates a deployment or runbook process using Azure…
Octopus Deploy
2020.3.4+
MEDIUM 6.5
CVE-2020-14470
In Octopus Deploy 2018.8.0 through 2019.x before 2019.12.2, an authenticated user with could trigger a deployment that leaks the Helm Chart repositor…
Octopus Deploy
2019.12.2+
HIGH 8.8
CVE-2020-10678
In Octopus Deploy before 2020.1.5, for customers running on-premises Active Directory linked to their Octopus server, an authenticated user can lever…
Octopus Deploy
2020.1.5+
MEDIUM 6.5
CVE-2019-19376
In Octopus Deploy before 2019.10.6, an authenticated user with TeamEdit permission could send a malformed Team API request that bypasses input valida…
Octopus Deploy
2019.6.14 / 2019.9.8+
MEDIUM 5.3
CVE-2019-19375
In Octopus Deploy before 2019.10.7, in a configuration where SSL offloading is enabled, the CSRF cookie was sometimes sent without the secure attribu…
Octopus Deploy
2019.6.14 / 2019.9.8+