CVE-2025-0539

In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests that contain authentication material allowing a suitably positioned attacker to compromise the account running Octopus Server and potentially the host infrastructure itself.
CVSS

No CVSS.

Configurations

No configuration.

History

15 Apr 2025, 21:15

Type Values Removed Values Added
CWE CWE-918

11 Apr 2025, 15:40

Type Values Removed Values Added
Summary
  • (es) En las versiones afectadas de Octopus Deploy para Microsoft Windows, el servidor puede ser obligado a realizar solicitudes del lado del servidor que contienen material de autenticación, lo que permite que un atacante adecuadamente posicionado comprometa la cuenta que ejecuta Octopus Server y potencialmente la propia infraestructura de envío del host.

10 Apr 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-10 06:15

Updated : 2025-04-15 21:15


NVD link : CVE-2025-0539

Mitre link : CVE-2025-0539

CVE.ORG link : CVE-2025-0539


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)