CyberRota Analysis
AI-GeneratedOctopus Server is vulnerable to insecure deserialization, allowing authenticated users with edit permissions for an Environment or Project to inject malicious JSON content. This can lead to arbitrary code execution within the Octopus Server process, posing a significant security risk. Organizations using Octopus Server should prioritize patching this vulnerability to protect their environments from potential exploitation.
Original NVD Description
In affected versions of Octopus Server, an authenticated user with permissions to edit an Environment or Project can set specifically crafted JSON content for the object. Insecure deserialization of this content allows the user to execute arbitrary code in the Octopus Server process.