Vulnerabilities > Octopus > Octopus Server > 3.11.2

DATE CVE VULNERABILITY TITLE RISK
2017-07-17 CVE-2017-11348 Path Traversal vulnerability in Octopus Deploy and Octopus Server
In Octopus Deploy 3.x before 3.15.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted NuGet package, potentially overwriting other packages or modifying system files.
network
octopus CWE-22
6.3