Security Advisory

CVE-2025-0539

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-04-10 05:20:38
Last updated 2025-04-15 20:25:25
Assigner Octopus
State PUBLISHED

Description

In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests that contain authentication material allowing a suitably positioned attacker to compromise the account running Octopus Server and potentially the host infrastructure itself.