Vulnerabilities > Octopus > Octopus Deploy > 1.3.5.1564

DATE CVE VULNERABILITY TITLE RISK
2022-02-07 CVE-2022-23184 Open Redirect vulnerability in Octopus Deploy
In affected Octopus Server versions when the server HTTP and HTTPS bindings are configured to localhost, Octopus Server will allow open redirects.
network
octopus CWE-601
5.8
2021-10-07 CVE-2021-26556 Untrusted Search Path vulnerability in Octopus Deploy
When Octopus Server is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL side-loading to gain privileged access.
local
low complexity
octopus CWE-426
7.8
2020-04-28 CVE-2020-12286 Information Exposure vulnerability in Octopus Deploy
In Octopus Deploy before 2019.12.9 and 2020 before 2020.1.12, the TaskView permission is not scoped to any dimension.
network
low complexity
octopus CWE-200
4.0
2020-03-19 CVE-2020-10678 Improper Privilege Management vulnerability in Octopus Deploy
In Octopus Deploy before 2020.1.5, for customers running on-premises Active Directory linked to their Octopus server, an authenticated user can leverage a bug to escalate privileges.
network
low complexity
octopus CWE-269
6.5
2019-02-20 CVE-2019-8944 Information Exposure Through Log Files vulnerability in Octopus Deploy
An Information Exposure issue in the Terraform deployment step in Octopus Deploy before 2019.1.8 (and before 2018.10.4 LTS) allows remote authenticated users to view sensitive Terraform output variables via log files.
network
low complexity
octopus CWE-532
4.0
2018-04-30 CVE-2018-10550 Improper Privilege Management vulnerability in Octopus Deploy
In Octopus Deploy before 2018.4.7, target and tenant tag variable scopes were not checked against the list of tenants the user has access to.
network
low complexity
octopus CWE-269
5.0
2018-01-16 CVE-2018-5706 Improper Privilege Management vulnerability in Octopus Deploy
An issue was discovered in Octopus Deploy before 4.1.9.
network
low complexity
octopus CWE-269
6.5
2017-12-13 CVE-2017-17665 Missing Authorization vulnerability in Octopus Deploy
In Octopus Deploy before 4.1.3, the machine update process doesn't check that the user has access to all environments.
network
low complexity
octopus CWE-862
6.5
2017-10-19 CVE-2017-15611 Incorrect Permission Assignment for Critical Resource vulnerability in Octopus Deploy
In Octopus before 3.17.7, an authenticated user who was explicitly granted the permission to invite new users (aka UserInvite) can invite users to teams with escalated privileges.
network
low complexity
octopus CWE-732
4.0
2017-10-19 CVE-2017-15610 Information Exposure vulnerability in Octopus Deploy
An issue was discovered in Octopus before 3.17.7.
network
low complexity
octopus CWE-200
4.0