In affected versions of Octopus Deploy where customers are using Active Directory for authentication it was possible for an unauthenticated user to make an API request against two endpoints which would retrieve some data from the associated Active Directory. The requests when crafted correctly would return specific information from user profiles (Email address/UPN and Display name) from one endpoint and group information ( Group ID and Display name) from the other. This vulnerability does not expose data within the Octopus Server product itself.
History

Tue, 11 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-648
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Feb 2025 09:15:00 +0000

Type Values Removed Values Added
Description In affected versions of Octopus Deploy where customers are using Active Directory for authentication it was possible for an unauthenticated user to make an API request against two endpoints which would retrieve some data from the associated Active Directory. The requests when crafted correctly would return specific information from user profiles (Email address/UPN and Display name) from one endpoint and group information ( Group ID and Display name) from the other. This vulnerability does not expose data within the Octopus Server product itself.
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Octopus

Published: 2025-02-11T08:59:51.030Z

Updated: 2025-02-11T15:20:52.205Z

Reserved: 2025-01-20T05:49:45.502Z

Link: CVE-2025-0589

cve-icon Vulnrichment

Updated: 2025-02-11T15:20:44.118Z

cve-icon NVD

Status : Received

Published: 2025-02-11T09:15:09.387

Modified: 2025-02-11T16:15:49.667

Link: CVE-2025-0589

cve-icon Redhat

No data.