← Vulnerability feed

Vulnerability record · CVE-2020-27155 · published 22 October 2020

CVE-2020-27155: Octopus deploy vulnerability

Octopus · Octopus Deploy

An issue was discovered in Octopus Deploy through 2020.4.4. If enabled, the websocket endpoint may allow an untrusted tentacle host to present itself as a trusted one.

7.5 CVSS 3.1 High EPSS 1.3% · top 31.4%
7.5CVSS 3.1 base score, v2 4.3
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Octopus Deploy through 2020.4.4. If enabled, the websocket endpoint may allow an untrusted tentacle host to present itself as a trusted one.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/OctopusDeploy Third Party Advisory
https://github.com/OctopusDeploy/Issues/issues/6637 Issue TrackingThird Party Advisory
https://github.com/OctopusDeploy/Issues/issues/6639 Issue TrackingPatchThird Party Advisory
https://github.com/OctopusDeploy/Issues/issues/6640 Issue TrackingPatchThird Party Advisory
https://github.com/OctopusDeploy Third Party Advisory
https://github.com/OctopusDeploy/Issues/issues/6637 Issue TrackingThird Party Advisory
https://github.com/OctopusDeploy/Issues/issues/6639 Issue TrackingPatchThird Party Advisory
https://github.com/OctopusDeploy/Issues/issues/6640 Issue TrackingPatchThird Party Advisory

Track CVE-2020-27155 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-10678Octopus deploy vulnerabilityIn Octopus Deploy before 2020.1.5, for customers running on-premises Active Directory linked to their Octopus server, an authenticated user can lever…EPSS 1.0%8.8CVE-2018-5706Octopus deploy improper privilege management vulnerabilityAn issue was discovered in Octopus Deploy before 4.1.9. Any user with user editing permissions can modify teams to give themselves Administer System …EPSS 1.0%8.8CVE-2018-4862Octopus deploy improper privilege management vulnerabilityIn Octopus Deploy versions 3.2.11 - 4.1.5 (fixed in 4.1.6), an authenticated user with ProcessEdit permission could reference an Azure account in suc…EPSS 1.1%8.8CVE-2017-17665Octopus deploy missing authorization vulnerabilityIn Octopus Deploy before 4.1.3, the machine update process doesn't check that the user has access to all environments. This allows an access-control …EPSS 1.1%8.1CVE-2019-11632Octopus deploy improper privilege management vulnerabilityIn Octopus Deploy 2019.1.0 through 2019.3.1 and 2019.4.0 through 2019.4.5, an authenticated user with the VariableViewUnscoped or VariableEditUnscope…EPSS 1.2%7.8CVE-2021-26556Octopus deploy untrusted search path vulnerabilityWhen Octopus Server is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL s…EPSS 0.26%7.5CVE-2022-2013Octopus deploy vulnerabilityIn Octopus Server after version 2022.1.1495 and before 2022.1.2647 if private spaces were enabled via the experimental feature flag all new users wou…EPSS 0.89%7.5CVE-2020-25825Octopus deploy vulnerabilityIn Octopus Deploy 3.1.0 to 2020.4.0, certain scripts can reveal sensitive information to the user in the task logs.EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2020-27155), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.