CVE-2024-4456: Octopus Server
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting payload on the audit page.
Affected products
- Octopus Octopus Server: from 3.0.0, before 2023.4.8338 (fixed in 2023.4.8338); from 2024.1.437, before 2024.1.11127 (fixed in 2024.1.11127)
Published 2024-05-08. Last modified 2026-06-17.