Vulnerabilities
Vulnerable Software
Octopus:  >> Octopus Server  Security Vulnerabilities
In Octopus Deploy 2018.4.4 through 2018.5.1, Octopus variables that are sourced from the target do not have sensitive values obfuscated in the deployment logs.
CVSS Score
9.8
EPSS Score
0.003
Published
2018-05-21
In Octopus Deploy 3.x before 3.15.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted NuGet package, potentially overwriting other packages or modifying system files. This is a directory traversal in the PackageId value.
CVSS Score
5.7
EPSS Score
0.006
Published
2017-07-17


Contact Us

Shodan ® - All rights reserved