Vulnerabilidades en Octopus Deploy

71 resultados
Análisis Vexday

Com 66 CVEs catalogadas e nenhuma entrada no catálogo CISA KEV, o Octopus Deploy apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere um perfil de risco operacional relativamente controlado no momento. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que, embora amplamente conhecido, exige atenção contínua em ferramentas de orquestração de deploys pela exposição a interfaces web. A CVE mais perigosa identificada atualmente é CVE-2021-31819, com score EPSS de 0,0228, indicando baixa probabilidade de exploração ativa iminente, mas ainda relevante para priorização em ambientes que não realizaram a correção. As 3 vulnerabilidades críticas catalogadas e as 2 CVEs surgidas nos últimos 90 dias reforçam a necessidade de manter o ciclo de patching atualizado, especialmente em pipelines de entrega contínua onde o impacto de uma comprometimento pode se propagar rapidamente por ambientes downstream.

CVE-2024-6972MEDIUMIn affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the task log in cEPSS 0.2%CVE-2023-4509MEDIUMIt is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt.EPSS 0.2%CVE-2026-14163HIGHIn affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the deployment vaEPSS 0.2%CVE-2021-31822When Octopus Tentacle is installed on a Linux operating system, the systemd service file permissions are misconfigured. This could lead to aEPSS 0.2%CVE-2026-4881MEDIUMIn affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make serverEPSS 0.2%CVE-2022-2781In affected versions of Octopus Server it was identified that the same encryption process was used for both encrypting session cookies and vEPSS 0.2%CVE-2026-12702MEDIUMIn affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deploymenEPSS 0.2%CVE-2021-31821When the Windows Tentacle docker image starts up it logs all the commands that it runs along with the arguments, which writes the Octopus SeEPSS 0.2%CVE-2022-4008MEDIUMIn affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of ServiceEPSS 0.2%CVE-2026-3236LOWIn affected versions of Octopus Server it was possible to create a new API key from an existing access token resulting in the new API key haEPSS 0.2%CVE-2026-3237LOWIn affected versions of Octopus Server it was possible for a low privileged user to manipulate an API request to change the signing key expiEPSS 0.2%