Home
MEDIUM: 5.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:L/VI:H/VA:L/SC:N/SI:N/SA:NDefault status
unaffected
2.6.0 (custom) before 2024.3.13071
affected
2024.4.401 (custom) before 2024.4.7065
affected
Description
In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests that contain authentication material allowing a suitably positioned attacker to compromise the account running Octopus Server and potentially the host infrastructure itself.
Problem types
Server Side Request Forgery
Product status
2.6.0 (custom) before 2024.3.13071
2024.4.401 (custom) before 2024.4.7065
Credits
This vulnerability was found by Edward Prior (@JankhJankh)
References
advisories.octopus.com/post/2025/sa2025-06