CVE-2023-2247
Octopus Deploy vulnerability analysis and mitigation

Overview

A vulnerability in Octopus Deploy (CVE-2023-2247) was discovered on November 10, 2022, and patched on April 6, 2023. The vulnerability allows the unmasking of variable secrets through the variable preview function, affecting multiple versions of Octopus Server including all 2018.3.x through 2021.x.x versions, and specific versions of 2022.x.x series before 2022.3.10929 and 2022.4.8319 (Octopus Advisory).

Technical details

The vulnerability has been assigned a CVSS v3.1 base score of 5.3 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N. This indicates that the vulnerability is network-accessible, requires low attack complexity, needs no privileges or user interaction, and can result in low-level confidentiality impact without affecting integrity or availability (NVD).

Impact

The vulnerability allows attackers to expose sensitive variable secrets through the variable preview functionality, potentially compromising the confidentiality of sensitive information stored in the system (Octopus Advisory).

Mitigation and workarounds

Octopus Deploy recommends upgrading to version 2023.1.9794 or later to address this vulnerability. For users unable to upgrade to the latest version, specific version upgrades are recommended: users on 2018.3.x through 2022.2.x should upgrade to 2022.3.10929 or greater, while users on 2022.4.x should upgrade to 2022.4.8319 or greater. There are no known alternative mitigations (Octopus Advisory).

Additional resources


SourceThis report was generated using AI

Related Octopus Deploy vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-0539MEDIUM5.9
  • Octopus DeployOctopus Deploy
  • cpe:2.3:a:octopus:octopus_server
NoYesApr 10, 2025
CVE-2025-0588MEDIUM5.9
  • Octopus DeployOctopus Deploy
  • cpe:2.3:a:octopus:octopus_server
NoYesFeb 11, 2025
CVE-2025-0526LOW2.3
  • Octopus DeployOctopus Deploy
  • cpe:2.3:a:octopus:octopus_server
NoYesFeb 11, 2025
CVE-2025-0525LOW2.3
  • Octopus DeployOctopus Deploy
  • cpe:2.3:a:octopus:octopus_server
NoYesFeb 11, 2025
CVE-2025-0513LOW1.8
  • Octopus DeployOctopus Deploy
  • cpe:2.3:a:octopus:octopus_server
NoYesFeb 11, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management