CVE Database
/

CVE-2025-0539

Back to search

CVE-2025-0539

Published: Apr 10, 2025

Modified: Apr 15, 2025

PUBLISHED

Description

In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests that contain authentication material allowing a suitably positioned attacker to compromise the account running Octopus Server and potentially the host infrastructure itself.

VendorProductVersions

Octopus Deploy

Octopus Server

affected
2.6.0 - < 2024.3.13071
affected
2024.4.401 - < 2024.4.7065

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now