Skip to main content

Vendor archive

octopus CVEs

Beta · best-effort

102 CVEs tagged to vendor octopus5 Critical, 31 High, 57 Medium, 9 Low, 0 Unrated.

CVE-2026-4881

Published Jun 4, 2026

In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level changes using a certain API endp…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-3237

Published Mar 17, 2026

In affected versions of Octopus Server it was possible for a low privileged user to manipulate an API request to change the signing key expiration and revocation time frames via a…

CVSS 2.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-3236

Published Mar 5, 2026

In affected versions of Octopus Server it was possible to create a new API key from an existing access token resulting in the new API key having a lifetime exceeding the original…

CVSS 2.3 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-0539

Published Apr 10, 2025

In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests that contain authentication material allowing a suitably posi…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-0526

Published Feb 11, 2025

In affected versions of Octopus Deploy it was possible to upload files to unexpected locations on the host using an API endpoint. The field lacked validation which could potential…

CVSS 2.3 · Low
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2024-4226

Published Apr 30, 2024

It was identified that in certain versions of Octopus Server, that a user created with no permissions could view all users, user roles and permissions. This functionality was remo…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-1904

Published Dec 14, 2023

In affected versions of Octopus Server it is possible for the OpenID client secret to be logged in clear text during the configuration of Octopus Server.

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2416

Published Aug 2, 2023

In affected versions of Octopus Deploy it is possible for a low privileged guest user to craft a request that allows enumeration/recon of an environment.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2346

Published Aug 2, 2023

In affected versions of Octopus Deploy it is possible for a low privileged guest user to interact with extension endpoints.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4870

Published May 18, 2023

In affected versions of Octopus Deploy it is possible to discover network details via error message

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4008

Published May 10, 2023

In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2247

Published May 2, 2023

In affected versions of Octopus Deploy it is possible to unmask variable secrets using the variable preview function

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 102 CVEsPage 1 of 5