Octopus

Octopus Server

63 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.08%
  • Veröffentlicht 02.08.2023 02:15:12
  • Zuletzt bearbeitet 21.11.2024 07:00:48

In affected versions of Octopus Deploy it is possible for a low privileged guest user to interact with extension endpoints.

  • EPSS 0.25%
  • Veröffentlicht 18.05.2023 00:15:09
  • Zuletzt bearbeitet 21.01.2025 21:15:08

In affected versions of Octopus Deploy it is possible to discover network details via error message

  • EPSS 0.04%
  • Veröffentlicht 10.05.2023 06:15:09
  • Zuletzt bearbeitet 28.01.2025 15:15:09

In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service

  • EPSS 0.31%
  • Veröffentlicht 19.04.2023 08:15:07
  • Zuletzt bearbeitet 05.02.2025 16:15:32

In affected versions of Octopus Deploy it is possible to render user supplied input into the webpage

  • EPSS 0.86%
  • Veröffentlicht 16.03.2023 04:15:12
  • Zuletzt bearbeitet 26.02.2025 21:15:12

In affected versions of Octopus Deploy it is possible for a user to introduce code via offline package creation

  • EPSS 0.18%
  • Veröffentlicht 13.03.2023 05:15:11
  • Zuletzt bearbeitet 03.03.2025 21:15:12

In affected versions of Octopus Deploy it is possible for a user to view Workerpools without being explicitly assigned permissions to view these items

  • EPSS 0.28%
  • Veröffentlicht 13.03.2023 05:15:11
  • Zuletzt bearbeitet 27.02.2025 22:15:34

In affected versions of Octopus Deploy it is possible for a user to view Tagsets without being explicitly assigned permissions to view these items

  • EPSS 0.54%
  • Veröffentlicht 22.02.2023 01:15:10
  • Zuletzt bearbeitet 11.03.2025 20:15:12

In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service

  • EPSS 0.21%
  • Veröffentlicht 31.01.2023 04:15:07
  • Zuletzt bearbeitet 27.03.2025 15:15:41

In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the support link. This was initially resolved in advisory 2022-07 however it was identified that the fix could be bypassed in certa...

  • EPSS 0.21%
  • Veröffentlicht 03.01.2023 02:15:16
  • Zuletzt bearbeitet 10.04.2025 15:15:50

In affected versions of Octopus Deploy users of certain browsers using AD to sign-in to Octopus Server were able to bypass authentication checks and be redirected to the configured redirect url without any validation.