Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p2h9-63jc-gj67

Опубликовано: 11 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 2.3
CVSS3: 7.5

Описание

In affected versions of Octopus Deploy it was possible to upload files to unexpected locations on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows.

In affected versions of Octopus Deploy it was possible to upload files to unexpected locations on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows.

EPSS

Процентиль: 30%
0.00114
Низкий

2.3 Low

CVSS4

7.5 High

CVSS3

Дефекты

CWE-22
CWE-862

Связанные уязвимости

CVSS3: 5.4
nvd
12 месяцев назад

In affected versions of Octopus Deploy it was possible to upload files to unexpected locations on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows.

EPSS

Процентиль: 30%
0.00114
Низкий

2.3 Low

CVSS4

7.5 High

CVSS3

Дефекты

CWE-22
CWE-862