Octopus Server, a popular automation tool for deployment, operations runbooks, and development tasks, has identified a critical security flaw.
The vulnerability tracked as CVE-2024-2975 could allow attackers to escalate privileges due to a race condition in the software.
The race condition vulnerability was discovered on February 20, 2024, and a patch was released on March 21, 2024.
Octopus Deploy issued an advisory on April 2, 2024, detailing the high-severity flaw that affects both Linux and Microsoft Windows operating systems.
The affected versions span across several years of Octopus Server releases:
Customers using any of these versions are urged to upgrade immediately to mitigate the risk posed by this vulnerability.
Trustifi’s Advanced threat protection prevents the widest spectrum of sophisticated attacks before they reach a user’s mailbox. Try Trustifi Free Threat Scan with Sophisticated AI-Powered Email Protection .
Octopus Deploy has not identified any known mitigations for CVE-2024-2975, making it crucial for users to upgrade to a fixed version.
The company has released the following patched versions of Octopus Server:
Octopus Deploy recommends upgrading to the latest version, 2024.1.12087, to ensure protection against the vulnerability.
For users unable to upgrade to the latest version, the following upgrade paths are advised:
Octopus Deploy’s security team has not observed any public announcements or malicious exploitation of CVE-2024-2975.
However, given the flaw’s severity, users are encouraged to take immediate action.
The discovery of CVE-2024-2975 reminds us of the importance of maintaining up-to-date software to safeguard against potential security threats.
Octopus Server users should review their installed versions and promptly upgrade to secure their systems from this high-severity vulnerability.
Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…