CVE-2025-0539: SSRF
In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests that contain authentication material allowing a suitably positioned attacker to compromise the account running Octopus Server and potentially the host infrastructure itself.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0539?
CVE-2025-0539 is considered a high severity vulnerability due to its potential to compromise accounts running Octopus Server.
How do I remediate CVE-2025-0539?
To fix CVE-2025-0539, users should update to the latest version of Octopus Deploy provided by Microsoft.
What does CVE-2025-0539 affect?
CVE-2025-0539 affects Microsoft Windows versions of Octopus Deploy.
Who is at risk from CVE-2025-0539?
Users of Octopus Deploy who are running affected Microsoft Windows versions are at risk from CVE-2025-0539.
What can an attacker do with CVE-2025-0539?
An attacker exploiting CVE-2025-0539 can potentially compromise the account running Octopus Server and the underlying host infrastructure.