Octopus

Octopus Server

65 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.39%
  • Veröffentlicht 14.12.2023 08:15:36
  • Zuletzt bearbeitet 21.11.2024 07:40:06

In affected versions of Octopus Server it is possible for the OpenID client secret to be logged in clear text during the configuration of Octopus Server.

  • EPSS 0.3%
  • Veröffentlicht 02.08.2023 06:15:10
  • Zuletzt bearbeitet 21.11.2024 07:00:56

In affected versions of Octopus Deploy it is possible for a low privileged guest user to craft a request that allows enumeration/recon of an environment.

  • EPSS 0.34%
  • Veröffentlicht 02.08.2023 02:15:12
  • Zuletzt bearbeitet 21.11.2024 07:00:48

In affected versions of Octopus Deploy it is possible for a low privileged guest user to interact with extension endpoints.

  • EPSS 0.45%
  • Veröffentlicht 18.05.2023 00:15:09
  • Zuletzt bearbeitet 21.01.2025 21:15:08

In affected versions of Octopus Deploy it is possible to discover network details via error message

  • EPSS 0.18%
  • Veröffentlicht 10.05.2023 06:15:09
  • Zuletzt bearbeitet 28.01.2025 15:15:09

In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service

  • EPSS 0.42%
  • Veröffentlicht 19.04.2023 08:15:07
  • Zuletzt bearbeitet 05.02.2025 16:15:32

In affected versions of Octopus Deploy it is possible to render user supplied input into the webpage

  • EPSS 0.72%
  • Veröffentlicht 16.03.2023 04:15:12
  • Zuletzt bearbeitet 26.02.2025 21:15:12

In affected versions of Octopus Deploy it is possible for a user to introduce code via offline package creation

  • EPSS 0.44%
  • Veröffentlicht 13.03.2023 05:15:11
  • Zuletzt bearbeitet 03.03.2025 21:15:12

In affected versions of Octopus Deploy it is possible for a user to view Workerpools without being explicitly assigned permissions to view these items

  • EPSS 0.5%
  • Veröffentlicht 13.03.2023 05:15:11
  • Zuletzt bearbeitet 27.02.2025 22:15:34

In affected versions of Octopus Deploy it is possible for a user to view Tagsets without being explicitly assigned permissions to view these items

  • EPSS 1.02%
  • Veröffentlicht 22.02.2023 01:15:10
  • Zuletzt bearbeitet 11.03.2025 20:15:12

In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service