CVE-2025-0513

EUVD-2025-1728
In affected versions of Octopus Server error messages were handled unsafely on the error page. If an adversary could control any part of the error message they could embed code which may impact the user viewing the error message.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 18%
Affected Products (NVD)
VendorProductVersion
octopusoctopus_server
2024.3.164 ≤
𝑥
< 2024.3.12985
octopusoctopus_server
2024.4.401 ≤
𝑥
< 2024.4.6962
𝑥
= Vulnerable software versions