{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aapachetomcat11.0.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*","cpe:2.3:a:apache:tomcat:11.0.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":6.5,"id":"CVE-2024-52317"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Octopus Deploy"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Octopus Deploy"],"content_html":"\u003cp\u003eOctopus Deploy is affected by a critical remote code execution vulnerability, identified as CVE-2024-52317. The flaw stems from improper input validation within the application, which allows an unauthenticated attacker to inject and execute arbitrary code on the underlying host server. This vulnerability poses a significant risk to CI/CD pipelines, as successful exploitation provides the attacker with execution privileges on the build server, potentially leading to unauthorized deployments, credential theft, or further lateral movement within the production environment. Organizations using Octopus Deploy for automated software release management should prioritize investigation and patching.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an unauthenticated attacker to gain full code execution on the Octopus Deploy server. This compromise can lead to the exfiltration of sensitive environment secrets, manipulation of deployment artifacts, and the ability to push malicious code into downstream production environments. The scope of impact is critical for any organization relying on Octopus Deploy as a central hub for CI/CD operations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching all internet-facing and internal instances of Octopus Deploy to the version specified in the vendor's security advisory. Monitor web server logs for anomalous POST requests or unexpected process spawning from the Octopus Deploy application process, as these are common indicators of exploitation attempts against web-based RCE flaws.\u003c/p\u003e\n","date_modified":"2026-09-29T16:18:53Z","date_published":"2026-09-29T16:18:53Z","id":"https://feed.craftedsignal.io/briefs/2026-09-octopus-deploy-rce/","summary":"An unauthenticated remote code execution vulnerability, tracked as CVE-2024-52317, exists in Octopus Deploy due to improper input validation.","title":"Remote Code Execution Vulnerability in Octopus Deploy","url":"https://feed.craftedsignal.io/briefs/2026-09-octopus-deploy-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:apache:tomcat:11.0.0:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}