CVE-2022-2074: High severity octopus deploy vulnerability
Published Aug 19, 2022
·Updated
In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service using the Variable Project Template.
Affected Software
14 affected components
Octopus Octopus Server>=0.9<=0.9.620.4
Octopus Octopus Server>=1.0<=1.6.3.1723
Octopus Octopus Server>=2.0<=2.6.5
Octopus Octopus Server>=3.0.0<=3.17.14
Octopus Octopus Server>=4.0.4<=4.1.10
Octopus Octopus Server>=2018.1.0<=2018.12.1
Octopus Octopus Server>=2019.1.0<=2019.13.7
Octopus Octopus Server>=2020.1.0<=2020.6.5449
Octopus Octopus Server>=2021.1.6959<=2021.3.13021
Octopus Octopus Server>=2022.1.0<2022.1.2894
Octopus Octopus Server>=2022.2.6729<2022.2.6872
Octopus Octopus Server>=2022.3.348<2022.3.4953
Linux Linux kernel
Microsoft Windows
Remediation
Patch Available
Event History
Aug 19, 2022
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-2074?
CVE-2022-2074 has been classified as a low severity vulnerability.
2
How do I fix CVE-2022-2074?
To fix CVE-2022-2074, upgrade to a version of Octopus Deploy that is not vulnerable.
3
Which versions of Octopus Deploy are affected by CVE-2022-2074?
CVE-2022-2074 affects multiple versions of Octopus Deploy ranging from 0.9 to 2022.3.348.
4
What type of vulnerability is CVE-2022-2074?
CVE-2022-2074 is a Regex Denial of Service vulnerability.
5
Is there a known exploit for CVE-2022-2074?
As of now, there are no publicly known exploits specifically targeting CVE-2022-2074.