Loading HuntDB...

Version 0.9

MAJOR_MINOR 12 CVEs

Known Vulnerabilities

CVE-2024-2975

A race condition was identified through which privilege escalation was possible in certain configurations.

HIGH CVSS 8.8 Published Apr 09, 2024

CVE-2022-2507

In affected versions of Octopus Deploy it is possible to render user supplied input into the webpage

UNKNOWN CVSS 5.3 Published Apr 19, 2023

CVE-2022-2883

In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service

UNKNOWN CVSS 7.5 Published Feb 22, 2023

CVE-2022-2508

In affected versions of Octopus Server it is possible to reveal the existence of resources in a space that the user does not have access to due to verbose error messaging.

UNKNOWN CVSS 5.3 Published Oct 27, 2022

CVE-2022-2782

In affected versions of Octopus Server it is possible for a session token to be valid indefinitely due to improper validation of the session token parameters.

UNKNOWN CVSS 9.1 Published Oct 26, 2022

CVE-2022-2075

In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service targeting the build information request validation.

UNKNOWN Published Aug 19, 2022

CVE-2022-2074

In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service using the Variable Project Template.

UNKNOWN Published Aug 19, 2022

CVE-2022-2049

In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service via the package upload function.

UNKNOWN Published Aug 19, 2022

CVE-2022-30532

In affected versions of Octopus Deploy, there is no logging of changes to artifacts within Octopus Deploy.

UNKNOWN Published Jul 19, 2022

CVE-2022-1670

When generating a user invitation code in Octopus Server, the validity of this code can be set for a specific number of users. It was possible to bypass this restriction of validity to create extra user accounts above the initial number of invited users.

UNKNOWN Published May 19, 2022

CVE-2021-26556

When Octopus Server is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL side-loading to gain privileged access.

UNKNOWN Published Oct 07, 2021

CVE-2021-31816

When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the OctopusServer.txt log file in plaintext.

UNKNOWN Published Jul 08, 2021