First published: Tue Feb 11 2025(Updated: )
In affected versions of Octopus Server error messages were handled unsafely on the error page. If an adversary could control any part of the error message they could embed code which may impact the user viewing the error message.
Credit: security@octopus.com
Affected Software | Affected Version | How to fix |
---|---|---|
Octopus Deploy |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0513 is classified as a medium severity vulnerability.
To fix CVE-2025-0513, upgrade to the latest version of Octopus Server that has addressed the error message handling issue.
CVE-2025-0513 affects all versions of Octopus Server prior to the patch release addressing this vulnerability.
CVE-2025-0513 is a code injection vulnerability due to unsafe handling of error messages.
The potential impact of CVE-2025-0513 includes the execution of embedded code, which could compromise the user viewing the error message.