Export limit exceeded: 21121 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (111 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2021-26557 | 1 Octopus | 1 Tentacle | 2024-11-21 | 7.8 High |
| When Octopus Tentacle is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL side-loading to gain privileged access. | ||||
| CVE-2021-26556 | 1 Octopus | 2 Octopus Deploy, Octopus Server | 2024-11-21 | 7.8 High |
| When Octopus Server is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL side-loading to gain privileged access. | ||||
| CVE-2021-21270 | 1 Octopus | 1 Octopusdsc | 2024-11-21 | 6.2 Medium |
| OctopusDSC is a PowerShell module with DSC resources that can be used to install and configure an Octopus Deploy Server and Tentacle agent. In OctopusDSC version 4.0.977 and earlier a customer API key used to connect to Octopus Server is exposed via logging in plaintext. This vulnerability is patched in version 4.0.1002. | ||||
| CVE-2020-27155 | 1 Octopus | 1 Octopus Deploy | 2024-11-21 | 7.5 High |
| An issue was discovered in Octopus Deploy through 2020.4.4. If enabled, the websocket endpoint may allow an untrusted tentacle host to present itself as a trusted one. | ||||
| CVE-2020-26161 | 1 Octopus | 1 Octopus Deploy | 2024-11-21 | 6.1 Medium |
| In Octopus Deploy through 2020.4.2, an attacker could redirect users to an external site via a modified HTTP Host header. | ||||
| CVE-2020-25825 | 1 Octopus | 1 Octopus Deploy | 2024-11-21 | 7.5 High |
| In Octopus Deploy 3.1.0 to 2020.4.0, certain scripts can reveal sensitive information to the user in the task logs. | ||||
| CVE-2020-24566 | 1 Octopus | 1 Octopus Deploy | 2024-11-21 | 7.5 High |
| In Octopus Deploy 2020.3.x before 2020.3.4 and 2020.4.x before 2020.4.1, if an authenticated user creates a deployment or runbook process using Azure steps and sets the step's execution location to run on the server/worker, then (under certain circumstances) the account password is exposed in cleartext in the verbose task logs output. | ||||
| CVE-2020-16197 | 1 Octopus | 2 Octopus Server, Server | 2024-11-21 | 4.3 Medium |
| An issue was discovered in Octopus Deploy 3.4. A deployment target can be configured with an Account or Certificate that is outside the scope of the deployment target. An authorised user can potentially use a certificate that they are not in scope to use. An authorised user is also able to obtain certificate metadata by associating a certificate with certain resources that should fail scope validation. | ||||
| CVE-2020-14470 | 1 Octopus | 1 Octopus Deploy | 2024-11-21 | 6.5 Medium |
| In Octopus Deploy 2018.8.0 through 2019.x before 2019.12.2, an authenticated user with could trigger a deployment that leaks the Helm Chart repository password. | ||||
| CVE-2020-12286 | 1 Octopus | 1 Octopus Deploy | 2024-11-21 | 4.3 Medium |
| In Octopus Deploy before 2019.12.9 and 2020 before 2020.1.12, the TaskView permission is not scoped to any dimension. For example, a scoped user who is scoped to only one tenant can view server tasks scoped to any other tenant. | ||||
| CVE-2020-10678 | 1 Octopus | 1 Octopus Deploy | 2024-11-21 | 8.8 High |
| In Octopus Deploy before 2020.1.5, for customers running on-premises Active Directory linked to their Octopus server, an authenticated user can leverage a bug to escalate privileges. | ||||
| CVE-2019-8944 | 1 Octopus | 2 Octopus Deploy, Octopus Server | 2024-11-21 | N/A |
| An Information Exposure issue in the Terraform deployment step in Octopus Deploy before 2019.1.8 (and before 2018.10.4 LTS) allows remote authenticated users to view sensitive Terraform output variables via log files. | ||||
| CVE-2019-19376 | 1 Octopus | 1 Octopus Deploy | 2024-11-21 | 6.5 Medium |
| In Octopus Deploy before 2019.10.6, an authenticated user with TeamEdit permission could send a malformed Team API request that bypasses input validation and causes an application level denial of service condition. (The fix for this was also backported to LTS 2019.9.8 and LTS 2019.6.14.) | ||||
| CVE-2019-19375 | 1 Octopus | 1 Octopus Deploy | 2024-11-21 | 5.3 Medium |
| In Octopus Deploy before 2019.10.7, in a configuration where SSL offloading is enabled, the CSRF cookie was sometimes sent without the secure attribute. (The fix for this was backported to LTS versions 2019.6.14 and 2019.9.8.) | ||||
| CVE-2019-19085 | 1 Octopus | 1 Server | 2024-11-21 | 5.4 Medium |
| A persistent cross-site scripting (XSS) vulnerability in Octopus Server 3.4.0 through 2019.10.5 allows remote authenticated attackers to inject arbitrary web script or HTML. | ||||
| CVE-2019-19084 | 1 Octopus | 1 Octopus Deploy | 2024-11-21 | 4.3 Medium |
| In Octopus Deploy 3.3.0 through 2019.10.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted package, triggering an exception that exposes underlying operating system details. | ||||
| CVE-2019-15698 | 1 Octopus | 1 Octopus Server | 2024-11-21 | N/A |
| In Octopus Deploy 2019.7.3 through 2019.7.9, in certain circumstances, an authenticated user with VariableView permissions could view sensitive values. This is fixed in 2019.7.10. | ||||
| CVE-2019-15508 | 1 Octopus | 2 Server, Tentacle | 2024-11-21 | N/A |
| In Octopus Tentacle versions 3.0.8 to 5.0.0, when a web request proxy is configured, an authenticated user (in certain limited OctopusPrintVariables circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is fixed in 5.0.1. The fix was back-ported to 4.0.7. | ||||
| CVE-2019-15507 | 1 Octopus | 1 Server | 2024-11-21 | N/A |
| In Octopus Deploy versions 2018.8.4 to 2019.7.6, when a web request proxy is configured, an authenticated user (in certain limited special-characters circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is fixed in 2019.7.7. The fix was back-ported to LTS 2019.6.7 as well as LTS 2019.3.8. | ||||
| CVE-2019-14525 | 1 Octopus | 2 Octopus Deploy, Octopus Server | 2024-11-21 | N/A |
| In Octopus Deploy 2019.4.0 through 2019.6.x before 2019.6.6, and 2019.7.x before 2019.7.6, an authenticated system administrator is able to view sensitive values by visiting a server configuration page or making an API call. | ||||