Vulnerability index

Browse CVEs

82 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Octopus Server MEDIUM 6.5
CVE-2026-4881

In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level ch…

Fix: 2025.4.10545 / 2026.1.11313+
Fix from $1,600 2026-06-04
Octopus Server CRITICAL 9.1
CVE-2026-0704

In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked va…

Fix: 2025.3.14715+
Fix from $2,300 2026-02-25
Octopus Server HIGH 8.8
CVE-2025-0539

In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests that contain authentication mat…

Fix: 2024.3.13071 / 2024.4.7065+
Fix from $1,950 2025-04-10
Octopus Server MEDIUM 5.4
CVE-2025-0513

In affected versions of Octopus Server error messages were handled unsafely on the error page. If an adversary could control any part of the error me…

Fix: 2024.3.12985 / 2024.4.6962+
Fix from $1,600 2025-02-11
Octopus Server MEDIUM 5.4
CVE-2025-0526

In affected versions of Octopus Deploy it was possible to upload files to unexpected locations on the host using an API endpoint. The field lacked va…

Fix: 2024.3.13097 / 2024.4.7091+
Fix from $1,600 2025-02-11
Octopus Server HIGH 7.5
CVE-2025-0525

In affected versions of Octopus Server the preview import feature could be leveraged to identify the existence of a target file. This could provide a…

Fix: 2024.3.13007 / 2024.4.6995+
Fix from $1,950 2025-02-11
Octopus Server MEDIUM 5.3
CVE-2025-0589

In affected versions of Octopus Deploy where customers are using Active Directory for authentication it was possible for an unauthenticated user to m…

Fix: 2024.3.13071 / 2024.4.7065+
Fix from $1,600 2025-02-11
Octopus Server CRITICAL 9.8
CVE-2024-9194

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Linux and Microsoft Windows Octopus Server on W…

Fix: 2024.1.13038 / 2024.2.9482+
Fix from $2,300 2024-09-30
Octopus Server MEDIUM 6.5
CVE-2024-6972

In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the task log in clear-text.

Fix: 2024.1.12759 / 2024.2.9193+
Fix from $1,600 2024-07-25
Octopus Server MEDIUM 5.4
CVE-2024-4456

In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting payload on the audit page.

Fix: 2023.4.8338 / 2024.1.11127+
Fix from $1,600 2024-05-08
Octopus Server HIGH 7.5
CVE-2024-2975

A race condition was identified through which privilege escalation was possible in certain configurations.

Fix: 2023.4.8432 / 2024.1.12087+
Fix from $1,950 2024-04-09
Octopus Server HIGH 7.5
CVE-2023-1904

In affected versions of Octopus Server it is possible for the OpenID client secret to be logged in clear text during the configuration of Octopus Ser…

Fix: 2023.1.11942 / 2023.2.13151+
Fix from $1,950 2023-12-14
Octopus Server MEDIUM 5.3
CVE-2022-4870

In affected versions of Octopus Deploy it is possible to discover network details via error message

Fix: 2023.1.9879 / 2023.2.8159+
Fix from $1,600 2023-05-18
Octopus Server MEDIUM 5.5
CVE-2022-4008

In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service

Fix: 2022.3.11043 / 2022.4.8401+
Fix from $1,600 2023-05-10
Octopus Deploy MEDIUM 5.3
CVE-2023-2247

In affected versions of Octopus Deploy it is possible to unmask variable secrets using the variable preview function

Fix: 2022.3.10929 / 2022.4.8319+
Fix from $1,600 2023-05-02
Octopus Server MEDIUM 5.3
CVE-2022-2507

In affected versions of Octopus Deploy it is possible to render user supplied input into the webpage

Fix: 2022.4.8332 / 2023.1.6715+
Fix from $1,600 2023-04-19
Octopus Server HIGH 8.8
CVE-2022-4009

In affected versions of Octopus Deploy it is possible for a user to introduce code via offline package creation

Fix: 2022.2.8552 / 2022.3.10750+
Fix from $1,950 2023-03-16
Octopus Server HIGH 7.5
CVE-2022-2883

In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service

Fix: 2022.3.11043 / 2022.4.8401+
Fix from $1,950 2023-02-22
Octopus Server MEDIUM 5.4
CVE-2022-4898

In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the support link. This was ini…

Fix: 2022.2.8552 / 2022.3.10750+
Fix from $1,600 2023-01-31
Octopus Server MEDIUM 6.1
CVE-2022-3614

In affected versions of Octopus Deploy users of certain browsers using AD to sign-in to Octopus Server were able to bypass authentication checks and …

Fix: 2022.3.10750 / 2022.4.8063+
Fix from $1,600 2023-01-03
Octopus Server HIGH 7.5
CVE-2022-3460

In affected versions of Octopus Deploy it is possible for certain types of sensitive variables to inadvertently become unmasked when viewed in variab…

Fix: 2022.3.10750 / 2022.4.8063+
Fix from $1,950 2023-01-03
Octopus Server HIGH 7.5
CVE-2022-2721

In affected versions of Octopus Server it is possible for target discovery to print certain values marked as sensitive to log files in plaint-text in…

Fix: 2022.2.7965 / 2022.3.9163+
Fix from $1,950 2022-11-25
Octopus Server CRITICAL 9.8
CVE-2022-2572

In affected versions of Octopus Server where access is managed by an external authentication provider, it was possible that the API key/keys of a dis…

Fix: 2022.1.3264 / 2022.2.8277+
Fix from $2,300 2022-11-01
Octopus Server CRITICAL 9.1
CVE-2022-2782

In affected versions of Octopus Server it is possible for a session token to be valid indefinitely due to improper validation of the session token pa…

Fix: 2022.2.8351 / 2022.3.10586+
Fix from $2,300 2022-10-27
Octopus Server MEDIUM 5.3
CVE-2022-2508

In affected versions of Octopus Server it is possible to reveal the existence of resources in a space that the user does not have access to due to ve…

Fix: 2022.1.3264 / 2022.2.8351+
Fix from $1,600 2022-10-27
Octopus Server HIGH 8.1
CVE-2022-2780

In affected versions of Octopus Server it is possible to use the Git Connectivity test function on the VCS project to initiate an SMB request resulti…

Fix: 2022.1.3180 / 2022.2.7965+
Fix from $1,950 2022-10-14
Octopus Server MEDIUM 6.5
CVE-2022-2828

In affected versions of Octopus Server it is possible to reveal information about teams via the API due to an Insecure Direct Object Reference (IDOR)…

Fix: after 2022.3.10586
Fix from $1,600 2022-10-13
Octopus Server MEDIUM 5.3
CVE-2022-2720

In affected versions of Octopus Server it was identified that when a sensitive value is a substring of another value, sensitive value masking will on…

Fix: 2022.1.3154 / 2022.2.7934+
Fix from $1,600 2022-10-12
Octopus Server MEDIUM 5.3
CVE-2022-2781

In affected versions of Octopus Server it was identified that the same encryption process was used for both encrypting session cookies and variables.

Fix: 2022.1.3154 / 2022.2.7897+
Fix from $1,600 2022-10-06
Octopus Server MEDIUM 5.3
CVE-2022-2783

In affected versions of Octopus Server it was identified that a session cookie could be used as the CSRF token

Fix: 2022.1.3154 / 2022.2.7897+
Fix from $1,600 2022-10-06