Octopus Server
cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*, +1 more
- ~2023
- ~2024
- ~2025.1
- ~2025.2
- ~2025.3
A vulnerability in Octopus Deploy's API allows for file deletion or modification on the host. This issue arises from a lack of proper validation in the API endpoint, which could be exploited to bypass intended workflows. The vulnerability affects Octopus Server versions 2023.x, 2024.x, 2025.1.x, 2025.2.x, and 2025.3.x prior to 2025.3.14715.
Exploitation of this vulnerability could lead to unauthorized file deletion or modification on the host system.
Users are advised to upgrade to Octopus Server version 2025.4.10446 or, if on version 2025.3.x, to upgrade to version 2025.3.14715. For those on the 2025.4.x version, upgrade to 2025.4.10359 or greater.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.