Inedo develops a focused suite of build-automation, configuration-management, and package-management tools (BuildMaster, Otter, and ProGet) that operate in critical infrastructure-deployment pipelines, and its vulnerabilities skew strongly toward critical-severity outcomes. The exposure recurs through web-application and access-control weakness classes including improper input validation, cross-site scripting, path traversal, cross-site request forgery, and improper privilege management, reflecting the authenticated-user and administrative-access context of these deployment-tier products. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Inedo over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-15607CRITICAL Inedo Otter before 1.7.4 has directory traversal in filesystem-based rafts via vectors involving '/' characters or initial '.' characters, aka OT-181. | Dec 1, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-16521CRITICAL In Inedo BuildMaster before 5.8.2, XslTransform was used where XslCompiledTransform should have been used. | Nov 10, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-17086CRITICAL Indeo Otter through 1.7.4 mishandles a "</script>" substring in an initial DP payload, which allows remote attackers to cause a denial of service (crash) or possibly have unspecifi | Dec 1, 2017 | 9.8 | 29 | NO | NO |
CVE-2017-16520HIGH Inedo BuildMaster before 5.8.2 does not properly restrict creation of RequireManageAllPrivileges event listeners. | Nov 11, 2017 | 7.5 | 24 | NO | NO |
CVE-2017-14944HIGH Inedo ProGet before 4.7.14 does not properly address dangerous package IDs during package addition, aka PG-1060. | Sep 30, 2017 | 7.5 | 24 | NO | NO |
CVE-2017-15608MEDIUM Inedo ProGet before 5.0 Beta5 has CSRF, allowing an attacker to change advanced settings. | Sep 26, 2018 | 6.5 | 22 | NO | NO |
CVE-2025-47244HIGH Inedo ProGet through 2024.22 allows remote attackers to reach restricted functionality through the C# reflection layer, as demonstrated by causing a denial of service (when an atta | May 3, 2025 | 7.3 | 21 | NO | NO |
CVE-2017-16761MEDIUM An Open Redirect vulnerability in Inedo BuildMaster before 5.8.2 allows remote attackers to redirect users to arbitrary web sites. | Nov 10, 2017 | 6.1 | 21 | NO | NO |
CVE-2017-16760MEDIUM Inedo BuildMaster before 5.8.2 has XSS. | Nov 10, 2017 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Inedo.
Media articles that mention a CVE ID that affects a product developed by Inedo — matched by CVE ID, not by vendor name.