Octopus Deploy Security Advisories
Home
Advisories icon
2021 2022 2023 2024 2025
Severity Levels
Disclosure Policy
  • Security Advisory 2023-08

    May 10, 2023 · Vulnerability/Denial of Service Severity/medium CVSS/6.5

    Zipbomb resource exhaustion in Tentacle (CVE-2022-4008)

    Read More
  • Security Advisory 2023-07

    Apr 26, 2023 · Vulnerability/Variable Secret Exposure Severity/low CVSS/3.8

    Variable preview can unmask secrets (CVE-2023-2247)

    Read More
  • Security Advisory 2023-06

    Apr 19, 2023 · Vulnerability/Cross-Site Scripting (XSS) Severity/low CVSS/2.5

    Weak Content Security Policy Header (CVE-2022-2507)

    Read More
  • Security Advisory 2023-05

    Mar 13, 2023 · Vulnerability/Improper Neutralisation of Special Elements used in a Command Severity/low CVSS/3.9

    Command injection via offline package creation (CVE-2022-4009)

    Read More
  • Security Advisory 2023-03

    Mar 10, 2023 · Vulnerability/Incorrect Privilege Assignment Severity/low CVSS/3.1

    Able to view tagsets without assigned permissions (CVE-2022-2258)

    Read More
  • Security Advisory 2023-04

    Mar 10, 2023 · Vulnerability/Incorrect Privilege Assignment Severity/low CVSS/3.1

    Able to view workerpools without assigned permissions (CVE-2022-2259)

    Read More
  • Security Advisory 2023-02

    Feb 14, 2023 · Vulnerability/Denial of Service Severity/medium CVSS/6.5

    Zipbomb resource exhaustion in Octopus Server (CVE-2022-2883)

    Read More
  • Security Advisory 2023-01

    Jan 30, 2023 · Vulnerability/Stored XSS Severity/medium CVSS/6.8

    Stored Cross-Site Scripting (XSS) in Octopus Server help sidebar (CVE-2022-4898)

    Read More
  • Security Advisory 2022-26

    Dec 22, 2022 · Vulnerability/Authentication Bypass Using an Alternate Path or Channel Severity/low CVSS/2.4

    Certain browsers can bypass authentication and redirect to the configured redirect url without any validation (CVE-2022-3614)

    Read More
  • Security Advisory 2022-25

    Dec 21, 2022 · Vulnerability/Exposure of Sensitive Information Through Environmental Variables Severity/medium CVSS/5.9

    Certain types of sensitive variables may be displayed as plain text in variable preview (CVE-2022-3460)

    Read More
    • ««
    • «
    • 1
    • 2
    • 3
    • 4
    • 5
    • »
    • »»

Recent Security Advisories

  • Security Advisory 2025-06
  • Security Advisory 2025-05
  • Security Advisory 2025-04
  • Security Advisory 2025-03
  • Security Advisory 2025-02
  • Security Advisory 2025-01
  • Security Advisory 2024-10
  • Security Advisory 2024-09

Products

OCTOPUS SERVER 59 OCTOPUS TENTACLE 4 OCTOPUS DEPLOY TEAMCITY PLUGIN 3 OCTOPUS JAVA SDK 3 HALIBUT 1 KUBERNETES WORKER AND AGENT 1

Tags

SEVERITY/MEDIUM 36 SEVERITY/LOW 23 SEVERITY/HIGH 12 VULNERABILITY/INFORMATION EXPOSURE 7 VULNERABILITY/VULNERABLE-DEPENDENCY 6 CVSS/6.5 5 VULNERABILITY/BROKEN ACCESS CONTROL 5 VULNERABILITY/CLEAR-TEXT-STORAGE-OF-SENSITIVE-VALUE 5 VULNERABILITY/STORED XSS 4 CVSS/5.5 3 CVSS/5.7 3 CVSS/5.9 3 CVSS/6.4 3 CVSS/6.8 3
All Tags
CVSS/1.81 CVSS/2.22 CVSS/2.32 CVSS/2.41 CVSS/2.51 CVSS/2.62 CVSS/3.01 CVSS/3.12 CVSS/3.41 CVSS/3.52 CVSS/3.61 CVSS/3.81 CVSS/3.91 CVSS/4.12 CVSS/4.21 CVSS/4.32 CVSS/4.91 CVSS/5.31 CVSS/5.41 CVSS/5.53 CVSS/5.73 CVSS/5.93 CVSS/6.32 CVSS/6.43 CVSS/6.55 CVSS/6.83 CVSS/6.91 CVSS/7.11 CVSS/7.31 CVSS/8.01 CVSS/8.71 CVSS/8.81 SEVERITY/HIGH12 SEVERITY/LOW23 SEVERITY/MEDIUM36 VULNERABILITY/ABNORMAL INVITE CODE FUNCTIONALITY1 VULNERABILITY/AUTHENTICATION BYPASS BY CAPTURE-REPLAY1 VULNERABILITY/AUTHENTICATION BYPASS USING AN ALTERNATE PATH OR CHANNEL1 VULNERABILITY/BROKEN ACCESS CONTROL5 VULNERABILITY/CLEAR-TEXT-STORAGE-OF-SENSITIVE-VALUE5 VULNERABILITY/CROSS-SITE SCRIPTING (XSS)1 VULNERABILITY/CSRF1 VULNERABILITY/DENIAL OF SERVICE3 VULNERABILITY/ENCRYPTION1 VULNERABILITY/EXPOSURE OF SENSITIVE INFORMATION THROUGH ENVIRONMENTAL VARIABLES1 VULNERABILITY/IMPROPER NEUTRALISATION OF SPECIAL ELEMENTS USED IN A COMMAND1 VULNERABILITY/IMPROPER RESTRICTION OF RENDERED UI LAYERS OR FRAMES1 VULNERABILITY/INCORRECT AUTHORISATION1 VULNERABILITY/INCORRECT PRIVILEGE ASSIGNMENT3 VULNERABILITY/INFORMATION DISCLOSURE2 VULNERABILITY/INFORMATION EXPOSURE7 VULNERABILITY/INSECURE DIRECT OBJECT REFERENCE (IDOR)1 VULNERABILITY/INSERTION OF SENSITIVE INFORMATION INTO LOG FILE1 VULNERABILITY/INSUFFICIENT SESSION EXPIRATION2 VULNERABILITY/LOCAL-PRIVILEGE-ESCALATION3 VULNERABILITY/LOGGING1 VULNERABILITY/OBSERVABLE DISCREPANCY1 VULNERABILITY/OPEN-REDIRECT1 VULNERABILITY/PATH TRAVERSAL1 VULNERABILITY/PRIVILEGE-ESCALATION1 VULNERABILITY/RATE LIMIT BYPASS1 VULNERABILITY/REGEX DENIAL OF SERVICE3 VULNERABILITY/REMOTE-CODE-EXECUTION3 VULNERABILITY/SENSITIVE VARIABLE EXPOSURE1 VULNERABILITY/SERVER-SIDE REQUEST FORGERY2 VULNERABILITY/SERVER-SIDE REQUEST FORGERY (SSRF)1 VULNERABILITY/SQL-INJECTION2 VULNERABILITY/STORED XSS4 VULNERABILITY/VARIABLE SECRET EXPOSURE1 VULNERABILITY/VULNERABLE-DEPENDENCY6
[A~Z][0~9]
 Octopus Deploy Security Advisories

Copyright   OCTOPUS DEPLOY SECURITY ADVISORIES. All Rights Reserved