Home/Product/octopus deploy
Product

octopus deploy

33 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-2247
>= 2018.3.0 and < 2022.3.10929
In affected versions of Octopus Deploy it is possible to unmask variable secrets using the variable preview function
5.3MEDIUM
CVE-2022-2013
>= 2022.1.1495 and < 2022.1.2647
In Octopus Server after version 2022.1.1495 and before 2022.1.2647 if private spaces were enabled via the experimental feature fla
7.5HIGH
CVE-2022-23184
>= 0.9 and <= 4.1.10
In affected Octopus Server versions when the server HTTP and HTTPS bindings are configured to localhost, Octopus Server will allow
6.1MEDIUM
CVE-2021-26556
>= 0.9 and < 2020.4.229
When Octopus Server is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileg
7.8HIGH
CVE-2020-26161
>= 2019.8.2 and <= 2020.4.2
In Octopus Deploy through 2020.4.2, an attacker could redirect users to an external site via a modified HTTP Host header.
6.1MEDIUM
CVE-2020-27155
>= 3.11.13 and <= 2020.4.4
An issue was discovered in Octopus Deploy through 2020.4.4. If enabled, the websocket endpoint may allow an untrusted tentacle hos
7.5HIGH
CVE-2020-25825
>= 3.1.0 and <= 2020.4.0
In Octopus Deploy 3.1.0 to 2020.4.0, certain scripts can reveal sensitive information to the user in the task logs.
7.5HIGH
CVE-2020-24566
>= 2020.3 and < 2020.3.4
In Octopus Deploy 2020.3.x before 2020.3.4 and 2020.4.x before 2020.4.1, if an authenticated user creates a deployment or runbook
7.5HIGH
CVE-2020-14470
>= 2018.8.0 and < 2019.12.2
In Octopus Deploy 2018.8.0 through 2019.x before 2019.12.2, an authenticated user with could trigger a deployment that leaks the H
6.5MEDIUM
CVE-2020-12286
< 2019.12.9
In Octopus Deploy before 2019.12.9 and 2020 before 2020.1.12, the TaskView permission is not scoped to any dimension. For example,
4.3MEDIUM
CVE-2020-10678
< 2020.1.5
In Octopus Deploy before 2020.1.5, for customers running on-premises Active Directory linked to their Octopus server, an authentic
8.8HIGH
CVE-2019-19376
< 2019.10.7
In Octopus Deploy before 2019.10.6, an authenticated user with TeamEdit permission could send a malformed Team API request that by
6.5MEDIUM
CVE-2019-19375
< 2019.10.7
In Octopus Deploy before 2019.10.7, in a configuration where SSL offloading is enabled, the CSRF cookie was sometimes sent without
5.3MEDIUM
CVE-2019-19084
>= 3.3.0 and <= 2019.10.4
In Octopus Deploy 3.3.0 through 2019.10.4, an authenticated user with PackagePush permission to upload packages could upload a mal
4.3MEDIUM
CVE-2019-14525
>= 2019.4.0 and < 2019.6.6
In Octopus Deploy 2019.4.0 through 2019.6.x before 2019.6.6, and 2019.7.x before 2019.7.6, an authenticated system administrator i
4.9MEDIUM
CVE-2019-14268
>= 3.0.19 and <= 2019.7.2
In Octopus Deploy versions 3.0.19 to 2019.7.2, when a web request proxy is configured, an authenticated user (in certain limited c
6.5MEDIUM
CVE-2019-11632
>= 2019.1.0 and <= 2019.3.1
In Octopus Deploy 2019.1.0 through 2019.3.1 and 2019.4.0 through 2019.4.5, an authenticated user with the VariableViewUnscoped or
8.1HIGH
CVE-2019-1003071
all versions
Jenkins OctopusDeploy Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can
8.8HIGH
CVE-2019-1003027
<= 1.8.1
A server-side request forgery vulnerability exists in Jenkins OctopusDeploy Plugin 1.8.1 and earlier in OctopusDeployPlugin.java t
4.3MEDIUM
CVE-2019-8944
<= 2018.9.17
An Information Exposure issue in the Terraform deployment step in Octopus Deploy before 2019.1.8 (and before 2018.10.4 LTS) allows
6.5MEDIUM
CVE-2018-12884
all versions
In Octopus Deploy 3.0 onwards (before 2018.6.7), an authenticated user with incorrect permissions may be able to create Accounts u
6.5MEDIUM
CVE-2018-10581
>= 3.4.0 and < 2018.4.7
In Octopus Deploy 3.4.x before 2018.4.7, an authenticated user is able to view/update/save variable values within the Tenant Varia
5.4MEDIUM
CVE-2018-10550
< 2018.4.7
In Octopus Deploy before 2018.4.7, target and tenant tag variable scopes were not checked against the list of tenants the user has
7.5HIGH
CVE-2018-9039
>= 2.0 and < 2018.3.7
In Octopus Deploy 2.0 and later before 2018.3.7, an authenticated user, with variable edit permissions, can scope some variables t
6.5MEDIUM
CVE-2018-5706
< 4.1.9
An issue was discovered in Octopus Deploy before 4.1.9. Any user with user editing permissions can modify teams to give themselves
8.8HIGH
CVE-2018-4862
>= 3.2.11 and <= 4.1.5
In Octopus Deploy versions 3.2.11 - 4.1.5 (fixed in 4.1.6), an authenticated user with ProcessEdit permission could reference an A
8.8HIGH
CVE-2017-17665
< 4.1.3
In Octopus Deploy before 4.1.3, the machine update process doesn't check that the user has access to all environments. This allows
8.8HIGH
CVE-2017-16810
>= 3.4.0 and <= 3.13.6
Cross-site scripting (XSS) vulnerability in the All Variables tab in Octopus Deploy 3.4.0-3.13.6 (fixed in 3.13.7) allows remote a
5.4MEDIUM
CVE-2017-16801
>= 3.7.0 and <= 3.17.3
Cross-site scripting (XSS) vulnerability in Octopus Deploy 3.7.0-3.17.13 (fixed in 3.17.14) allows remote authenticated users to i
5.4MEDIUM
CVE-2017-15611
<= 3.17.6
In Octopus before 3.17.7, an authenticated user who was explicitly granted the permission to invite new users (aka UserInvite) can
6.5MEDIUM
CVE-2017-15610
<= 3.17.6
An issue was discovered in Octopus before 3.17.7. When the special Guest user account is granted the CertificateExportPrivateKey p
6.5MEDIUM
CVE-2017-15609
<= 3.17.6
Octopus before 3.17.7 allows attackers to obtain sensitive cleartext information by reading a variable JSON file in certain situat
7.5HIGH
CVE-2017-11348
all versions
In Octopus Deploy 3.x before 3.15.4, an authenticated user with PackagePush permission to upload packages could upload a malicious
5.7MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin