CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
In affected versions of Octopus Server it is possible for the OpenID client secret to be logged in clear text during the configuration of Octopus Server. | 7.5 |
High |
||
In affected versions of Octopus Deploy it is possible for a low privileged guest user to craft a request that allows enumeration/recon of an environment. | 5.5 |
Medium |
||
In affected versions of Octopus Deploy it is possible for a low privileged guest user to interact with extension endpoints. | 5.5 |
Medium |