← Back

CVE-2025-0526

nvd nist
Published: Feb 11, 2025Modified: Jun 17, 2026

JSON object

Loading...
2.3
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: security@octopus.com (Secondary)

Description

In affected versions of Octopus Deploy it was possible to upload files to unexpected locations on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows.

Affected (2)

1 product
Octopus Server
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Octopus
From 2022.4.791 to 2024.3.13097
From 2024.4.401 to 2024.4.7091
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (2)

Source: security@octopus.com
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.