CVE-2022-1881: Medium severity octopus deploy vulnerability
Published Jul 15, 2022
·Updated
In affected versions of Octopus Server an Insecure Direct Object Reference vulnerability exists where it is possible for a user to download Project Exports from a Project they do not have permissions to access. This vulnerability only impacts projects within the same Space.
Affected Software
4 affected components
Octopus Octopus Server>=2021.1.6959<2021.3.13021
Octopus Octopus Server>=2022.1.2121<2022.1.2894
Octopus Octopus Server>=2022.2.6729<2022.2.6971
Octopus Octopus Server>=2022.3.348<2022.3.2616
Event History
Jul 15, 2022
CVE Published
via MITRE·07:40 AM
Data Sourced
via MITRE·07:40 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-1881?
CVE-2022-1881 is an Insecure Direct Object Reference vulnerability in Octopus Server that allows unauthorized download of Project Exports within the same Space.
2
How severe is CVE-2022-1881?
CVE-2022-1881 has a severity value of 5.3, considered medium.
3
How can I fix CVE-2022-1881?
To fix CVE-2022-1881, it is recommended to update Octopus Server to a version that addresses this vulnerability.