<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:apache:tomcat:11.0.0:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aapachetomcat11.0.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 16:18:53 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aapachetomcat11.0.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Execution Vulnerability in Octopus Deploy</title><link>https://feed.craftedsignal.io/briefs/2026-09-octopus-deploy-rce/</link><pubDate>Tue, 29 Sep 2026 16:18:53 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-octopus-deploy-rce/</guid><description>An unauthenticated remote code execution vulnerability, tracked as CVE-2024-52317, exists in Octopus Deploy due to improper input validation.</description><content:encoded><![CDATA[<p>Octopus Deploy is affected by a critical remote code execution vulnerability, identified as CVE-2024-52317. The flaw stems from improper input validation within the application, which allows an unauthenticated attacker to inject and execute arbitrary code on the underlying host server. This vulnerability poses a significant risk to CI/CD pipelines, as successful exploitation provides the attacker with execution privileges on the build server, potentially leading to unauthorized deployments, credential theft, or further lateral movement within the production environment. Organizations using Octopus Deploy for automated software release management should prioritize investigation and patching.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows an unauthenticated attacker to gain full code execution on the Octopus Deploy server. This compromise can lead to the exfiltration of sensitive environment secrets, manipulation of deployment artifacts, and the ability to push malicious code into downstream production environments. The scope of impact is critical for any organization relying on Octopus Deploy as a central hub for CI/CD operations.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize patching all internet-facing and internal instances of Octopus Deploy to the version specified in the vendor's security advisory. Monitor web server logs for anomalous POST requests or unexpected process spawning from the Octopus Deploy application process, as these are common indicators of exploitation attempts against web-based RCE flaws.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>