{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2025-0513","assignerOrgId":"6f4f8c89-ef06-4bae-a2a5-6734ddf76272","state":"PUBLISHED","assignerShortName":"Octopus","dateReserved":"2025-01-16T06:52:12.103Z","datePublished":"2025-02-11T10:27:26.482Z","dateUpdated":"2025-02-11T14:41:18.275Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","platforms":["Windows","Linux"],"product":"Octopus Server","vendor":"Octopus Deploy","versions":[{"lessThan":"2024.3.12985","status":"affected","version":"2024.3.164","versionType":"custom"},{"lessThan":"2024.4.6962","status":"affected","version":"2024.4.401","versionType":"custom"}]}],"credits":[{"lang":"en","type":"finder","value":"This vulnerability was found by Edward Prior (@JankhJankh)"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"In affected versions of Octopus Server error messages were handled unsafely on the error page. If an adversary could control any part of the error message they could embed code which may impact the user viewing the error message."}],"value":"In affected versions of Octopus Server error messages were handled unsafely on the error page. If an adversary could control any part of the error message they could embed code which may impact the user viewing the error message."}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"HIGH","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":1.8,"baseSeverity":"LOW","privilegesRequired":"HIGH","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"ACTIVE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"description":"XSS in Octopus Deploy error page","lang":"en"}]}],"providerMetadata":{"orgId":"6f4f8c89-ef06-4bae-a2a5-6734ddf76272","shortName":"Octopus","dateUpdated":"2025-02-11T10:27:26.482Z"},"references":[{"url":"https://advisories.octopus.com/post/2024/sa2025-04/"}],"source":{"discovery":"EXTERNAL"},"x_generator":{"engine":"Vulnogram 0.1.0-dev"}},"adp":[{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-79","lang":"en","description":"CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-02-11T14:40:30.520706Z","id":"CVE-2025-0513","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-02-11T14:41:18.275Z"}}]}}