CVE-2022-2346
- EPSS 0.08%
- Veröffentlicht 02.08.2023 02:15:12
- Zuletzt bearbeitet 21.11.2024 07:00:48
In affected versions of Octopus Deploy it is possible for a low privileged guest user to interact with extension endpoints.
CVE-2022-4870
- EPSS 0.25%
- Veröffentlicht 18.05.2023 00:15:09
- Zuletzt bearbeitet 21.01.2025 21:15:08
In affected versions of Octopus Deploy it is possible to discover network details via error message
CVE-2022-4008
- EPSS 0.04%
- Veröffentlicht 10.05.2023 06:15:09
- Zuletzt bearbeitet 28.01.2025 15:15:09
In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service
CVE-2022-2507
- EPSS 0.31%
- Veröffentlicht 19.04.2023 08:15:07
- Zuletzt bearbeitet 05.02.2025 16:15:32
In affected versions of Octopus Deploy it is possible to render user supplied input into the webpage
CVE-2022-4009
- EPSS 0.86%
- Veröffentlicht 16.03.2023 04:15:12
- Zuletzt bearbeitet 26.02.2025 21:15:12
In affected versions of Octopus Deploy it is possible for a user to introduce code via offline package creation
CVE-2022-2259
- EPSS 0.18%
- Veröffentlicht 13.03.2023 05:15:11
- Zuletzt bearbeitet 03.03.2025 21:15:12
In affected versions of Octopus Deploy it is possible for a user to view Workerpools without being explicitly assigned permissions to view these items
CVE-2022-2258
- EPSS 0.28%
- Veröffentlicht 13.03.2023 05:15:11
- Zuletzt bearbeitet 27.02.2025 22:15:34
In affected versions of Octopus Deploy it is possible for a user to view Tagsets without being explicitly assigned permissions to view these items
CVE-2022-2883
- EPSS 0.54%
- Veröffentlicht 22.02.2023 01:15:10
- Zuletzt bearbeitet 11.03.2025 20:15:12
In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service
CVE-2022-4898
- EPSS 0.21%
- Veröffentlicht 31.01.2023 04:15:07
- Zuletzt bearbeitet 27.03.2025 15:15:41
In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the support link. This was initially resolved in advisory 2022-07 however it was identified that the fix could be bypassed in certa...
CVE-2022-3614
- EPSS 0.21%
- Veröffentlicht 03.01.2023 02:15:16
- Zuletzt bearbeitet 10.04.2025 15:15:50
In affected versions of Octopus Deploy users of certain browsers using AD to sign-in to Octopus Server were able to bypass authentication checks and be redirected to the configured redirect url without any validation.