Search
Find a vulnerability
Search criteria
2 vulnerabilities found for octopus_server by octopus
CVE-2023-4509 (GCVE-0-2023-4509)
Vulnerability from cvelistv5 โ Published: 2024-04-17 23:10 โ Updated: 2024-11-07 16:55
VLAI
EPSS
VEX
Summary
It is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt.
Severity
4.3 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator ยท CISA-ADP (v2.0.3)
Decision recorded 2024-04-23 19:18 UTC
CWE
- API key disclosed in Octopus Server audit log
- CWE-319 - Cleartext Transmission of Sensitive Information
Assigner
References
1 reference
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Octopus Deploy | Octopus Server |
Affected:
2018.9 , < 2023.4.296
(custom)
Affected: 2024.1 , < 2024.1.437 (custom) Affected: 2024.2 , < 2024.2.101 (custom) |
|
| octopus | octopus_server |
Affected:
2024.2 , < 2024.2.101
(custom)
cpe:2.3:a:octopus:octopus_server:-:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:a:octopus:octopus_server:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "octopus_server",
"vendor": "octopus",
"versions": [
{
"lessThan": "2024.2.101",
"status": "affected",
"version": "2024.2",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-4509",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-04-23T19:18:35.698764Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-319",
"description": "CWE-319 Cleartext Transmission of Sensitive Information",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-11-07T16:55:13.840Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2024-08-02T07:31:05.976Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://advisories.octopus.com/post/2024/sa2024-02/"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"Windows",
"Linux"
],
"product": "Octopus Server",
"vendor": "Octopus Deploy",
"versions": [
{
"lessThan": "2023.4.296",
"status": "affected",
"version": "2018.9",
"versionType": "custom"
},
{
"lessThan": "2024.1.437",
"status": "affected",
"version": "2024.1",
"versionType": "custom"
},
{
"lessThan": "2024.2.101",
"status": "affected",
"version": "2024.2",
"versionType": "custom"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "It is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt."
}
],
"value": "It is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "API key disclosed in Octopus Server audit log",
"lang": "en"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-09-18T07:12:55.561Z",
"orgId": "6f4f8c89-ef06-4bae-a2a5-6734ddf76272",
"shortName": "Octopus"
},
"references": [
{
"url": "https://advisories.octopus.com/post/2024/sa2024-02/"
}
],
"source": {
"discovery": "INTERNAL"
},
"x_generator": {
"engine": "Vulnogram 0.1.0-dev"
}
}
},
"cveMetadata": {
"assignerOrgId": "6f4f8c89-ef06-4bae-a2a5-6734ddf76272",
"assignerShortName": "Octopus",
"cveId": "CVE-2023-4509",
"datePublished": "2024-04-17T23:10:37.111Z",
"dateReserved": "2023-08-24T03:00:03.168Z",
"dateUpdated": "2024-11-07T16:55:13.840Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2024-2975 (GCVE-0-2024-2975)
Vulnerability from cvelistv5 โ Published: 2024-04-09 01:02 โ Updated: 2024-09-19 04:48
VLAI
EPSS
VEX
Summary
A race condition was identified through which privilege escalation was possible in certain configurations.
Severity
8.8 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator ยท CISA-ADP (v2.0.3)
Decision recorded 2024-04-09 17:03 UTC
CWE
- Race condition could lead to privilege escalation
- CWE-1223 - Race Condition for Write-Once Attributes
Assigner
References
1 reference
Impacted products
3 products
| Vendor | Product | Version | |
|---|---|---|---|
| Octopus Deploy | Octopus Server |
Affected:
0.9 , < 2023.4.8432
(custom)
Affected: 2024.1.437 , < 2024.1.12087 (custom) Affected: 2024.2.101 , < 2024.2.2075 (custom) |
|
| octopus | octopus_server |
Affected:
0.9 , < 2023.4.8432
(custom)
cpe:2.3:a:octopus:octopus_server:0.9:*:*:*:*:*:*:* |
|
| octopus | octopus_server |
Affected:
2024.1.437 , < 2024.1.12087
(custom)
Affected: 2024.2.101 , < 2024.2.2075 (custom) cpe:2.3:a:octopus:octopus_server:-:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:a:octopus:octopus_server:0.9:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "octopus_server",
"vendor": "octopus",
"versions": [
{
"lessThan": "2023.4.8432",
"status": "affected",
"version": "0.9",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:a:octopus:octopus_server:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "octopus_server",
"vendor": "octopus",
"versions": [
{
"lessThan": "2024.1.12087",
"status": "affected",
"version": "2024.1.437",
"versionType": "custom"
},
{
"lessThan": "2024.2.2075",
"status": "affected",
"version": "2024.2.101",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-2975",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-04-09T17:03:49.379549Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1223",
"description": "CWE-1223 Race Condition for Write-Once Attributes",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-06-19T22:04:50.605Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2024-08-01T19:32:42.513Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://advisories.octopus.com/post/2024/sa2024-01/"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"platforms": [
"Windows",
"Linux"
],
"product": "Octopus Server",
"vendor": "Octopus Deploy",
"versions": [
{
"lessThan": "2023.4.8432",
"status": "affected",
"version": "0.9",
"versionType": "custom"
},
{
"lessThan": "2024.1.12087",
"status": "affected",
"version": "2024.1.437",
"versionType": "custom"
},
{
"lessThan": "2024.2.2075",
"status": "affected",
"version": "2024.2.101",
"versionType": "custom"
}
]
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "A race condition was identified through which privilege escalation was possible in certain configurations."
}
],
"value": "A race condition was identified through which privilege escalation was possible in certain configurations."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Race condition could lead to privilege escalation",
"lang": "en"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-09-19T04:48:32.065Z",
"orgId": "6f4f8c89-ef06-4bae-a2a5-6734ddf76272",
"shortName": "Octopus"
},
"references": [
{
"url": "https://advisories.octopus.com/post/2024/sa2024-01/"
}
],
"source": {
"discovery": "EXTERNAL"
},
"x_generator": {
"engine": "Vulnogram 0.1.0-dev"
}
}
},
"cveMetadata": {
"assignerOrgId": "6f4f8c89-ef06-4bae-a2a5-6734ddf76272",
"assignerShortName": "Octopus",
"cveId": "CVE-2024-2975",
"datePublished": "2024-04-09T01:02:46.880Z",
"dateReserved": "2024-03-27T05:50:03.804Z",
"dateUpdated": "2024-09-19T04:48:32.065Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}