CVE-2017-16801: XSS
Published Nov 13, 2017
·Updated
Cross-site scripting (XSS) vulnerability in Octopus Deploy 3.7.0-3.17.13 (fixed in 3.17.14) allows remote authenticated users to inject arbitrary web script or HTML via the Step Template Name parameter.
Affected Software
1 affected component
Octopus Octopus Deploy>=3.7.0<=3.17.3
Event History
Nov 13, 2017
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-16801?
CVE-2017-16801 is categorized as a high-severity Cross-site Scripting (XSS) vulnerability.
2
How do I fix CVE-2017-16801?
To fix CVE-2017-16801, upgrade Octopus Deploy to version 3.17.14 or later.
3
Which versions of Octopus Deploy are affected by CVE-2017-16801?
CVE-2017-16801 affects Octopus Deploy versions from 3.7.0 to 3.17.3.
4
What type of vulnerability is CVE-2017-16801?
CVE-2017-16801 is a Cross-site Scripting (XSS) vulnerability that allows script injection.
5
Who is impacted by CVE-2017-16801?
Remote authenticated users are impacted by CVE-2017-16801 because they can exploit the vulnerability to inject scripts.