Vulnerabilities
Vulnerable Software
In Octopus Deploy before 2019.10.6, an authenticated user with TeamEdit permission could send a malformed Team API request that bypasses input validation and causes an application level denial of service condition. (The fix for this was also backported to LTS 2019.9.8 and LTS 2019.6.14.)
CVSS Score
6.5
EPSS Score
0.002
Published
2019-11-28
In Octopus Deploy 3.3.0 through 2019.10.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted package, triggering an exception that exposes underlying operating system details.
CVSS Score
4.3
EPSS Score
0.006
Published
2019-11-18


Contact Us

Shodan ® - All rights reserved