CVE-2025-0588 Details
Description
In affected versions of Octopus Server it was possible for a user with sufficient access to set custom headers in all server responses. By submitting a specifically crafted referrer header the user could ensure that all subsequent server responses would return 500 errors rendering the site mostly unusable. The user would be able to subsequently set and unset the referrer header to control the denial of service state with a valid CSRF token whilst new CSRF tokens could not be generated.
A denial-of-service vulnerability has been identified in Octopus Server. A user with sufficient access could manipulate server responses by setting custom headers, particularly the referrer header. This manipulation would cause subsequent server responses to return 500 errors, disrupting the site's functionality. The user could control this denial-of-service state by toggling the referrer header, using a valid CSRF token, while unable to generate new CSRF tokens. This issue affects all 2020.x, 2021.x, 2022.x, and 2023.x versions of Octopus Server, as well as all 2024.1.x, 2024.2.x, and 2024.3.x versions prior to 2023.3.13097. Users who have upgraded to Octopus Server version 2024.4.7132 or higher are not affected.
Users are advised to upgrade to Octopus Server version 2024.4.7091 or 2024.3.13097. The latest version can be downloaded from the Octopus Deploy website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 11, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://advisories.octopus.com/post/2024/sa2025-05/ | CISA-ADP | Broken Link |
| https://advisories.octopus.com/post/2025/sa2025-05/ | CISA-ADP | Vendor Advisory |
| https://advisories.octopus.com/post/2024/sa2025-05/ | [email protected] | Broken Link |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-113 | Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| octopus octopus server | >= 2020.1.0, < 2024.3.13097 >= 2024.4.401, < 2024.4.7091 |
CPE
Remediation
| |
| linux linux kernel | All versions |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 2, 2025 | Initial Analysis | [email protected] |
| Mar 13, 2025 | CVE Modified | CISA-ADP |
| Feb 11, 2025 | CVE Modified | CISA-ADP |
| Feb 11, 2025 | New CVE Received | [email protected] |