In affected versions of Octopus Server it was possible for a user with sufficient access to set custom headers in all server responses. By submitting a specifically crafted referrer header the user could ensure that all subsequent server responses would return 500 errors rendering the site mostly unusable. The user would be able to subsequently set and unset the referrer header to control the denial of service state with a valid CSRF token whilst new CSRF tokens could not be generated.
History

Thu, 13 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-113

Tue, 11 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Feb 2025 11:30:00 +0000

Type Values Removed Values Added
Description In affected versions of Octopus Server it was possible for a user with sufficient access to set custom headers in all server responses. By submitting a specifically crafted referrer header the user could ensure that all subsequent server responses would return 500 errors rendering the site mostly unusable. The user would be able to subsequently set and unset the referrer header to control the denial of service state with a valid CSRF token whilst new CSRF tokens could not be generated.
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Octopus

Published: 2025-02-11T11:22:27.034Z

Updated: 2025-03-13T15:30:38.062Z

Reserved: 2025-01-20T05:46:19.249Z

Link: CVE-2025-0588

cve-icon Vulnrichment

Updated: 2025-02-11T14:15:40.772Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-02-11T12:15:34.200

Modified: 2025-03-13T16:15:26.150

Link: CVE-2025-0588

cve-icon Redhat

No data.