CVE-2024-4811: Octopus Server

Low severity, CVSS 2.2. EPSS: 0.2% chance of exploitation in the next 30 days.

In affected versions of Octopus Server under certain conditions, a user with specific role assignments can access restricted project artifacts.

Affected products

  • Octopus Octopus Server: from 2023.1.4189, before 2023.4.8608 (fixed in 2023.4.8608); from 2024.1.437, before 2024.1.12759 (fixed in 2024.1.12759); from 2024.2.101, before 2024.2.9193 (fixed in 2024.2.9193)

Published 2024-07-25. Last modified 2026-06-17.