Total vulnerabilities in the database
In Octopus Deploy 3.3.0 through 2019.10.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted package, triggering an exception that exposes underlying operating system details.
Software | From | Fixed in |
---|---|---|
octopus / octopus_deploy | 3.3.0 | 2019.10.4.x |