Vulnerabilities > Octopus > Low

DATE CVE VULNERABILITY TITLE RISK
2022-01-19 CVE-2021-31821 Cleartext Storage of Sensitive Information vulnerability in Octopus Tentacle
When the Windows Tentacle docker image starts up it logs all the commands that it runs along with the arguments, which writes the Octopus Server API key in plaintext.
local
low complexity
octopus CWE-312
2.1
2021-01-22 CVE-2021-21270 Cleartext Transmission of Sensitive Information vulnerability in Octopus Octopusdsc
OctopusDSC is a PowerShell module with DSC resources that can be used to install and configure an Octopus Deploy Server and Tentacle agent.
local
low complexity
octopus CWE-319
2.1
2019-11-18 CVE-2019-19085 Cross-site Scripting vulnerability in Octopus Server
A persistent cross-site scripting (XSS) vulnerability in Octopus Server 3.4.0 through 2019.10.5 allows remote authenticated attackers to inject arbitrary web script or HTML.
network
octopus CWE-79
3.5
2019-08-23 CVE-2019-15507 Cleartext Storage of Sensitive Information vulnerability in Octopus Server
In Octopus Deploy versions 2018.8.4 to 2019.7.6, when a web request proxy is configured, an authenticated user (in certain limited special-characters circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext.
network
octopus CWE-312
3.5
2019-08-23 CVE-2019-15508 Cleartext Storage of Sensitive Information vulnerability in Octopus Server and Tentacle
In Octopus Tentacle versions 3.0.8 to 5.0.0, when a web request proxy is configured, an authenticated user (in certain limited OctopusPrintVariables circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext.
network
octopus CWE-312
3.5
2018-06-11 CVE-2018-12089 Information Exposure vulnerability in Octopus Server
In Octopus Deploy version 2018.5.1 to 2018.5.7, a user with Task View is able to view a password for a Service Fabric Cluster, when the Service Fabric Cluster target is configured in Azure Active Directory security mode and a deployment is executed with OctopusPrintVariables set to True.
network
octopus CWE-200
3.5
2017-11-14 CVE-2017-16810 Cross-site Scripting vulnerability in Octopus Deploy
Cross-site scripting (XSS) vulnerability in the All Variables tab in Octopus Deploy 3.4.0-3.13.6 (fixed in 3.13.7) allows remote attackers to inject arbitrary web script or HTML via the Variable Set Name parameter.
network
octopus CWE-79
3.5
2017-11-13 CVE-2017-16801 Cross-site Scripting vulnerability in Octopus Deploy
Cross-site scripting (XSS) vulnerability in Octopus Deploy 3.7.0-3.17.13 (fixed in 3.17.14) allows remote authenticated users to inject arbitrary web script or HTML via the Step Template Name parameter.
network
octopus CWE-79
3.5