Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
71 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.51% | — | Octopus Server | 9/9/2022 | 17/6/2026 | In affected versions of Octopus Deploy it is possible to upload a package to built-in feed with insufficient permissions after re-indexing packages. | |
| Modificada | Alta (7.5) | 0.75% | — | Octopus Server | 19/8/2022 | 17/6/2026 | In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service targeting the build information request validation. | |
| Modificada | Alta (7.5) | 0.85% | — | Octopus Server | 19/8/2022 | 17/6/2026 | In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service using the Variable Project Template. | |
| Modificada | Alta (7.5) | 0.75% | — | Octopus Server | 19/8/2022 | 17/6/2026 | In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service via the package upload function. | |
| Modificada | Media (5.3) | 0.54% | — | Octopus Server | 19/8/2022 | 17/6/2026 | In affected versions of Octopus Deploy it is possible to unmask sensitive variables by using variable preview. | |
| Modificada | Media (5.3) | 0.54% | — | Octopus Server | 19/7/2022 | 17/6/2026 | In affected versions of Octopus Deploy, there is no logging of changes to artifacts within Octopus Deploy. | |
| Modificada | Media (6.1) | 0.47% | — | Octopus Server | 15/7/2022 | 17/6/2026 | In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the support link. | |
| Modificada | Media (5.3) | 0.56% | — | Octopus Server | 15/7/2022 | 17/6/2026 | In affected versions of Octopus Server an Insecure Direct Object Reference vulnerability exists where it is possible for a user to download Project Exports from a Project they do not have permissions to access. This vulnerability only impacts projects within the same Space. | |
| Modificada | Alta (7.5) | 0.84% | — | Octopus Server | 19/5/2022 | 17/6/2026 | When generating a user invitation code in Octopus Server, the validity of this code can be set for a specific number of users. It was possible to bypass this restriction of validity to create extra user accounts above the initial number of invited users. | |
| Modificada | Media (6.1) | 0.56% | — | Octopus DeployOctopus Server | 7/2/2022 | 17/6/2026 | In affected Octopus Server versions when the server HTTP and HTTPS bindings are configured to localhost, Octopus Server will allow open redirects. | |
| Modificada | Alta (7.8) | 0.26% | — | Octopus DeployOctopus Server | 7/10/2021 | 17/6/2026 | When Octopus Server is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL side-loading to gain privileged access. | |
| Modificada | Alta (7.5) | 0.61% | — | Octopus Server | 18/8/2021 | 17/6/2026 | In Octopus Server after version 2018.8.2 if the Octopus Server Web Request Proxy is configured with authentication, the password is shown in plaintext in the UI. | |
| Modificada | Media (4.3) | 0.55% | — | Octopus ServerOctopus Server | 25/8/2020 | 17/6/2026 | An issue was discovered in Octopus Deploy 3.4. A deployment target can be configured with an Account or Certificate that is outside the scope of the deployment target. An authorised user can potentially use a certificate that they are not in scope to use. An authorised user is also able to obtain certificate metadata… | |
| Modificada | Media (4.3) | 0.88% | — | Octopus Server | 27/8/2019 | 17/6/2026 | In Octopus Deploy 2019.7.3 through 2019.7.9, in certain circumstances, an authenticated user with VariableView permissions could view sensitive values. This is fixed in 2019.7.10. | |
| Modificada | Media (4.9) | 1.5% | — | Octopus DeployOctopus Server | 5/8/2019 | 17/6/2026 | In Octopus Deploy 2019.4.0 through 2019.6.x before 2019.6.6, and 2019.7.x before 2019.7.6, an authenticated system administrator is able to view sensitive values by visiting a server configuration page or making an API call. | |
| Modificada | Alta (8.1) | 1.2% | — | Octopus DeployOctopus Server | 1/5/2019 | 17/6/2026 | In Octopus Deploy 2019.1.0 through 2019.3.1 and 2019.4.0 through 2019.4.5, an authenticated user with the VariableViewUnscoped or VariableEditUnscoped permission scoped to a specific project could view or edit unscoped variables from a different project. (These permissions are only used in custom User Roles and do not… | |
| Modificada | Media (6.5) | 1.5% | — | Octopus DeployOctopus Server | 20/2/2019 | 17/6/2026 | An Information Exposure issue in the Terraform deployment step in Octopus Deploy before 2019.1.8 (and before 2018.10.4 LTS) allows remote authenticated users to view sensitive Terraform output variables via log files. | |
| Modificada | Alta (8.8) | 12% | 💥 Exploit | Octopus Server | 31/10/2018 | 17/6/2026 | In Octopus Deploy 2018.8.0 through 2018.9.x before 2018.9.1, an authenticated user with permission to modify deployment processes could upload a maliciously crafted YAML configuration, potentially allowing for remote execution of arbitrary code, running in the same context as the Octopus Server (for self-hosted… | |
| Modificada | Alta (7.5) | 0.93% | — | Octopus Server | 11/6/2018 | 17/6/2026 | In Octopus Deploy version 2018.5.1 to 2018.5.7, a user with Task View is able to view a password for a Service Fabric Cluster, when the Service Fabric Cluster target is configured in Azure Active Directory security mode and a deployment is executed with OctopusPrintVariables set to True. This is fixed in 2018.6.0. | |
| Modificada | Crítica (9.8) | 1.4% | — | Octopus Server | 21/5/2018 | 17/6/2026 | In Octopus Deploy 2018.4.4 through 2018.5.1, Octopus variables that are sourced from the target do not have sensitive values obfuscated in the deployment logs. | |
| Modificada | Media (5.7) | 1.2% | — | Octopus DeployOctopus Server | 17/7/2017 | 17/6/2026 | In Octopus Deploy 3.x before 3.15.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted NuGet package, potentially overwriting other packages or modifying system files. This is a directory traversal in the PackageId value. |