Vulnerabilidades em Octopus Deploy

71 resultados
Análise Vexday

Com 66 CVEs catalogadas e nenhuma entrada no catálogo CISA KEV, o Octopus Deploy apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere um perfil de risco operacional relativamente controlado no momento. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que, embora amplamente conhecido, exige atenção contínua em ferramentas de orquestração de deploys pela exposição a interfaces web. A CVE mais perigosa identificada atualmente é CVE-2021-31819, com score EPSS de 0,0228, indicando baixa probabilidade de exploração ativa iminente, mas ainda relevante para priorização em ambientes que não realizaram a correção. As 3 vulnerabilidades críticas catalogadas e as 2 CVEs surgidas nos últimos 90 dias reforçam a necessidade de manter o ciclo de patching atualizado, especialmente em pipelines de entrega contínua onde o impacto de uma comprometimento pode se propagar rapidamente por ambientes downstream.

CVE-2023-1904MEDIUMIn affected versions of Octopus Server it is possible for the OpenID client secret to be logged in clear text during the configuration of OcEPSS 0.4%CVE-2025-0525LOWIn affected versions of Octopus Server the preview import feature could be leveraged to identify the existence of a target file. This could EPSS 0.4%CVE-2025-0589MEDIUMIn affected versions of Octopus Deploy where customers are using Active Directory for authentication it was possible for an unauthenticated EPSS 0.4%CVE-2025-0539MEDIUMIn affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests that contain authenticEPSS 0.4%CVE-2025-0526LOWIn affected versions of Octopus Deploy it was possible to upload files to unexpected locations on the host using an API endpoint. The field EPSS 0.4%CVE-2024-12226MEDIUMIn affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes script pod log in cleEPSS 0.4%CVE-2022-2346MEDIUMIn affected versions of Octopus Deploy it is possible for a low privileged guest user to interact with extension endpoints.EPSS 0.3%CVE-2026-0704MEDIUMIn affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field EPSS 0.3%CVE-2021-26557When Octopus Tentacle is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user EPSS 0.3%CVE-2026-8296MEDIUMIn affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Payload via artifacts.EPSS 0.3%CVE-2024-4226LOWIt was identified that in certain versions of Octopus Server, that a user created with no permissions could view all users, user roles and pEPSS 0.3%CVE-2022-2416MEDIUMIn affected versions of Octopus Deploy it is possible for a low privileged guest user to craft a request that allows enumeration/recon of anEPSS 0.3%CVE-2021-26556When Octopus Server is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user usEPSS 0.3%CVE-2026-91778HIGHIn affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a worker (including theEPSS 0.3%CVE-2024-4456MEDIUMIn affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting payload on the audit page.EPSS 0.3%CVE-2024-7998LOWIn affected versions of Octopus Server OIDC cookies were using the wrong expiration time which could result in them using the maximum lifespEPSS 0.2%CVE-2024-1656LOWAffected versions of Octopus Server had a weak content security policy.EPSS 0.2%CVE-2024-4811LOWIn affected versions of Octopus Server under certain conditions, a user with specific role assignments can access restricted project artifacEPSS 0.2%CVE-2025-0513LOWIn affected versions of Octopus Server error messages were handled unsafely on the error page. If an adversary could control any part of theEPSS 0.2%CVE-2022-2783In affected versions of Octopus Server it was identified that a session cookie could be used as the CSRF tokenEPSS 0.2%