In affected versions of Octopus Server the preview import feature could be leveraged to identify the existence of a target file. This could provide an adversary with information that may aid in further attacks against the server.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://advisories.octopus.com/post/2024/sa2025-02/ |
![]() ![]() |
History
Tue, 11 Feb 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-200 | |
Metrics |
cvssV3_1
|
Tue, 11 Feb 2025 10:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In affected versions of Octopus Server the preview import feature could be leveraged to identify the existence of a target file. This could provide an adversary with information that may aid in further attacks against the server. | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: Octopus
Published:
Updated: 2025-02-18T17:48:02.923Z
Reserved: 2025-01-17T02:42:42.838Z
Link: CVE-2025-0525

Updated: 2025-02-11T14:32:26.253Z

Status : Awaiting Analysis
Published: 2025-02-11T10:15:09.490
Modified: 2025-02-18T18:15:28.850
Link: CVE-2025-0525

No data.