← Back

CVE-2025-0588

nvd nist
Published: Feb 11, 2025Modified: Jun 17, 2026

JSON object

Loading...
5.9
Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: security@octopus.com (Secondary)

Description

In affected versions of Octopus Server it was possible for a user with sufficient access to set custom headers in all server responses. By submitting a specifically crafted referrer header the user could ensure that all subsequent server responses would return 500 errors rendering the site mostly unusable. The user would be able to subsequently set and unset the referrer header to control the denial of service state with a valid CSRF token whilst new CSRF tokens could not be generated.

Affected (2)

1 product
Octopus Server
Configuration A
2 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Octopus
From 2020.1.0 to 2024.3.13097
From 2024.4.401 to 2024.4.7091
Running on/withPlatform Versions
Linux
Linux Kernel
All versions
Microsoft
Windows
All versions

References (3)

Source: security@octopus.com
Broken Link
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Broken Link
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Vendor Advisory

Timeline

No history available yet.