Vulnerabilidades em Octopus Deploy

67 resultados
Análise Vexday

Com 66 CVEs catalogadas e nenhuma entrada no catálogo CISA KEV, o Octopus Deploy apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere um perfil de risco operacional relativamente controlado no momento. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que, embora amplamente conhecido, exige atenção contínua em ferramentas de orquestração de deploys pela exposição a interfaces web. A CVE mais perigosa identificada atualmente é CVE-2021-31819, com score EPSS de 0,0228, indicando baixa probabilidade de exploração ativa iminente, mas ainda relevante para priorização em ambientes que não realizaram a correção. As 3 vulnerabilidades críticas catalogadas e as 2 CVEs surgidas nos últimos 90 dias reforçam a necessidade de manter o ciclo de patching atualizado, especialmente em pipelines de entrega contínua onde o impacto de uma comprometimento pode se propagar rapidamente por ambientes downstream.

CVE-2021-31819In Halibut versions prior to 4.4.7 there is a deserialisation vulnerability that could allow remote code execution on systems that already tEPSS 2.4%CVE-2022-2883HIGHIn affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of ServiceEPSS 1.0%CVE-2022-2013In Octopus Server after version 2022.1.1495 and before 2022.1.2647 if private spaces were enabled via the experimental feature flag all new EPSS 0.9%CVE-2021-31816When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is writtenEPSS 0.9%CVE-2021-31817When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is writtenEPSS 0.9%CVE-2022-2572CRITICALIn affected versions of Octopus Server where access is managed by an external authentication provider, it was possible that the API key/keysEPSS 0.8%CVE-2022-1670When generating a user invitation code in Octopus Server, the validity of this code can be set for a specific number of users. It was possibEPSS 0.8%CVE-2022-2074In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service using the Variable Project Template.EPSS 0.8%CVE-2022-2778CRITICALIn affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes.EPSS 0.7%CVE-2022-4009HIGHIn affected versions of Octopus Deploy it is possible for a user to introduce code via offline package creationEPSS 0.7%CVE-2022-2075In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service targeting the build information request validatioEPSS 0.7%CVE-2022-2049In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service via the package upload function.EPSS 0.7%CVE-2021-31818Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API because user supplied dEPSS 0.6%CVE-2021-31820In Octopus Server after version 2018.8.2 if the Octopus Server Web Request Proxy is configured with authentication, the password is shown inEPSS 0.6%CVE-2022-23184In affected Octopus Server versions when the server HTTP and HTTPS bindings are configured to localhost, Octopus Server will allow open rediEPSS 0.6%CVE-2022-3460HIGHIn affected versions of Octopus Deploy it is possible for certain types of sensitive variables to inadvertently become unmasked when viewed EPSS 0.6%CVE-2022-2721HIGHIn affected versions of Octopus Server it is possible for target discovery to print certain values marked as sensitive to log files in plainEPSS 0.6%CVE-2022-2782CRITICALIn affected versions of Octopus Server it is possible for a session token to be valid indefinitely due to improper validation of the sessionEPSS 0.5%CVE-2022-2828MEDIUMIn affected versions of Octopus Server it is possible to reveal information about teams via the API due to an Insecure Direct Object ReferenEPSS 0.5%CVE-2022-1881In affected versions of Octopus Server an Insecure Direct Object Reference vulnerability exists where it is possible for a user to download EPSS 0.5%