CVE-2020-27155: High severity octopus deploy vulnerability
Published Oct 22, 2020
·Updated
An issue was discovered in Octopus Deploy through 2020.4.4. If enabled, the websocket endpoint may allow an untrusted tentacle host to present itself as a trusted one.
Affected Software
1 affected component
Octopus Octopus Deploy>=3.11.13<=2020.4.4
Remediation
Patch Available
Patch Available
Event History
Oct 22, 2020
CVE Published
via MITRE·04:48 PM
Data Sourced
via MITRE·04:48 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-27155?
CVE-2020-27155 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2020-27155?
To remediate CVE-2020-27155, you should upgrade Octopus Deploy to version 2020.4.5 or later.
3
What specific issue does CVE-2020-27155 address?
CVE-2020-27155 addresses a vulnerability in the websocket endpoint that could allow an untrusted tentacle host to impersonate a trusted one.
4
What versions of Octopus Deploy are affected by CVE-2020-27155?
CVE-2020-27155 affects Octopus Deploy versions from 3.11.13 to 2020.4.4.
5
Is it safe to use Octopus Deploy versions prior to 2020.4.5 due to CVE-2020-27155?
Using Octopus Deploy versions prior to 2020.4.5 is not safe as they are vulnerable to CVE-2020-27155.