在受影响版本的 Octopus Server 中,拥有编辑环境(Environment)或项目(Project)权限的已认证用户,可以为该对象设置特别构造的 JSON 内容。由于对该内容存在不安全反序列化漏洞,攻击者可借此在 Octopus Server 进程中执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Octopus Deploy | Octopus Server | 2019.4.1 ~ 2026.1.11781 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet