Vulnerabilities
Vulnerable Software
Octopus:  Security Vulnerabilities
When Octopus Tentacle is installed on a Linux operating system, the systemd service file permissions are misconfigured. This could lead to a local unprivileged user modifying the contents of the systemd service file to gain privileged access.
CVSS Score
7.8
EPSS Score
0.002
Published
2021-11-24
When Octopus Server is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL side-loading to gain privileged access.
CVSS Score
7.8
EPSS Score
0.003
Published
2021-10-07
When Octopus Tentacle is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL side-loading to gain privileged access.
CVSS Score
7.8
EPSS Score
0.003
Published
2021-10-07
In Halibut versions prior to 4.4.7 there is a deserialisation vulnerability that could allow remote code execution on systems that already trust each other based on certificate verification.
CVSS Score
9.8
EPSS Score
0.024
Published
2021-09-22
In Octopus Server after version 2018.8.2 if the Octopus Server Web Request Proxy is configured with authentication, the password is shown in plaintext in the UI.
CVSS Score
7.5
EPSS Score
0.006
Published
2021-08-18
When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the OctopusServer.txt log file in plaintext.
CVSS Score
7.5
EPSS Score
0.009
Published
2021-07-08
When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the OctopusServer.txt log file in plaintext.
CVSS Score
7.5
EPSS Score
0.009
Published
2021-07-08
Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API because user supplied data in the API request isn’t parameterised correctly. Exploiting this vulnerability could allow unauthorised access to database tables.
CVSS Score
4.3
EPSS Score
0.006
Published
2021-06-17
Cleartext storage of sensitive information in multiple versions of Octopus Server where in certain situations when running import or export processes, the password used to encrypt and decrypt sensitive values would be written to the logs in plaintext.
CVSS Score
7.5
EPSS Score
0.009
Published
2021-05-14
OctopusDSC is a PowerShell module with DSC resources that can be used to install and configure an Octopus Deploy Server and Tentacle agent. In OctopusDSC version 4.0.977 and earlier a customer API key used to connect to Octopus Server is exposed via logging in plaintext. This vulnerability is patched in version 4.0.1002.
CVSS Score
6.2
EPSS Score
0.003
Published
2021-01-22


Contact Us

Shodan ® - All rights reserved