Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
octopus deploy vulnerabilities and exploits
(subscribe to this query)
356
VMScore
CVE-2019-8944
An Information Exposure issue in the Terraform deployment step in Octopus Deploy prior to 2019.1.8 (and prior to 2018.10.4 LTS) allows remote authenticated users to view sensitive Terraform output variables via log files.
Octopus Octopus Deploy 2018.10.3
Octopus Octopus Deploy 2018.10.2
Octopus Octopus Deploy 2018.10.1
Octopus Octopus Deploy 2018.10.0
Octopus Octopus Deploy
Octopus Octopus Server
356
VMScore
CVE-2019-14525
In Octopus Deploy 2019.4.0 up to and including 2019.6.x prior to 2019.6.6, and 2019.7.x prior to 2019.7.6, an authenticated system administrator is able to view sensitive values by visiting a server configuration page or making an API call.
Octopus Octopus Deploy
Octopus Octopus Server
392
VMScore
CVE-2021-26556
When Octopus Server is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL side-loading to gain privileged access.
Octopus Octopus Deploy
Octopus Octopus Server
517
VMScore
CVE-2022-23184
In affected Octopus Server versions when the server HTTP and HTTPS bindings are configured to localhost, Octopus Server will allow open redirects.
Octopus Octopus Deploy
Octopus Octopus Server
490
VMScore
CVE-2019-11632
In Octopus Deploy 2019.1.0 up to and including 2019.3.1 and 2019.4.0 up to and including 2019.4.5, an authenticated user with the VariableViewUnscoped or VariableEditUnscoped permission scoped to a specific project could view or edit unscoped variables from a different project. (...
Octopus Octopus Deploy
Octopus Octopus Server
445
VMScore
CVE-2018-10550
In Octopus Deploy prior to 2018.4.7, target and tenant tag variable scopes were not checked against the list of tenants the user has access to.
Octopus Octopus Deploy
578
VMScore
CVE-2020-10678
In Octopus Deploy prior to 2020.1.5, for customers running on-premises Active Directory linked to their Octopus server, an authenticated user can leverage a bug to escalate privileges.
Octopus Octopus Deploy
383
VMScore
CVE-2020-24566
In Octopus Deploy 2020.3.x prior to 2020.3.4 and 2020.4.x prior to 2020.4.1, if an authenticated user creates a deployment or runbook process using Azure steps and sets the step's execution location to run on the server/worker, then (under certain circumstances) the account ...
Octopus Octopus Deploy
356
VMScore
CVE-2019-14268
In Octopus Deploy versions 3.0.19 to 2019.7.2, when a web request proxy is configured, an authenticated user (in certain limited circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is fixed in 2019.7.3. The...
Octopus Octopus Deploy
312
VMScore
CVE-2017-16801
Cross-site scripting (XSS) vulnerability in Octopus Deploy 3.7.0-3.17.13 (fixed in 3.17.14) allows remote authenticated users to inject arbitrary web script or HTML via the Step Template Name parameter.
Octopus Octopus Deploy
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27322
CVE-2006-4304
wireless
CVE-2023-23022
local file inclusion
CVE-2024-27058
CVE-2024-33820
open redirect
CVE-2024-27079
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »