CVE-2017-16810: XSS
Published Nov 14, 2017
·Updated
Cross-site scripting (XSS) vulnerability in the All Variables tab in Octopus Deploy 3.4.0-3.13.6 (fixed in 3.13.7) allows remote attackers to inject arbitrary web script or HTML via the Variable Set Name parameter.
Affected Software
1 affected component
Octopus Octopus Deploy>=3.4.0<=3.13.6
Event History
Nov 14, 2017
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-16810?
The severity of CVE-2017-16810 is classified as medium due to the possible XSS exploitation.
2
How do I fix CVE-2017-16810?
To fix CVE-2017-16810, upgrade to Octopus Deploy version 3.13.7 or later.
3
What is the impact of CVE-2017-16810?
CVE-2017-16810 allows remote attackers to execute arbitrary web scripts or HTML in the context of the user's browser.
4
Which versions of Octopus Deploy are affected by CVE-2017-16810?
Octopus Deploy versions 3.4.0 to 3.13.6 are affected by CVE-2017-16810.
5
Is CVE-2017-16810 related to XSS vulnerabilities?
Yes, CVE-2017-16810 is a cross-site scripting (XSS) vulnerability specifically in the Variable Set Name parameter.