CVE-2025-0513: XSS
In affected versions of Octopus Server error messages were handled unsafely on the error page. If an adversary could control any part of the error message they could embed code which may impact the user viewing the error message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0513?
CVE-2025-0513 is classified as a medium severity vulnerability.
How do I fix CVE-2025-0513?
To fix CVE-2025-0513, upgrade to the latest version of Octopus Server that has addressed the error message handling issue.
What versions of Octopus Server are affected by CVE-2025-0513?
CVE-2025-0513 affects all versions of Octopus Server prior to the patch release addressing this vulnerability.
What type of vulnerability is CVE-2025-0513?
CVE-2025-0513 is a code injection vulnerability due to unsafe handling of error messages.
What are the potential impacts of CVE-2025-0513?
The potential impact of CVE-2025-0513 includes the execution of embedded code, which could compromise the user viewing the error message.