Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5h88-xc4r-2q76

Опубликовано: 10 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.9
CVSS3: 8.8

Описание

In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests that contain authentication material allowing a suitably positioned attacker to compromise the account running Octopus Server and potentially the host infrastructure itself.

In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests that contain authentication material allowing a suitably positioned attacker to compromise the account running Octopus Server and potentially the host infrastructure itself.

EPSS

Процентиль: 34%
0.0014
Низкий

5.9 Medium

CVSS4

8.8 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 8.8
nvd
10 месяцев назад

In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests that contain authentication material allowing a suitably positioned attacker to compromise the account running Octopus Server and potentially the host infrastructure itself.

EPSS

Процентиль: 34%
0.0014
Низкий

5.9 Medium

CVSS4

8.8 High

CVSS3

Дефекты

CWE-918