CVE-2022-2075: High severity octopus deploy vulnerability
Published Aug 19, 2022
·Updated
In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service targeting the build information request validation.
Affected Software
14 affected components
Octopus Octopus Server>=0.9<=0.9.620.4
Octopus Octopus Server>=1.0<=1.6.3.1723
Octopus Octopus Server>=2.0<=2.6.5
Octopus Octopus Server>=3.0.0<=3.17.14
Octopus Octopus Server>=4.0.4<=4.1.10
Octopus Octopus Server>=2018.1.0<=2018.12.1
Octopus Octopus Server>=2019.1.0<=2019.13.7
Octopus Octopus Server>=2020.1.0<=2020.6.5449
Octopus Octopus Server>=2021.1.6959<=2021.3.13021
Octopus Octopus Server>=2022.1.0<2022.1.2894
Octopus Octopus Server>=2022.2.6729<2022.2.6872
Octopus Octopus Server>=2022.3.348<2022.3.4953
Linux Linux kernel
Microsoft Windows
Remediation
Patch Available
Event History
Aug 19, 2022
CVE Published
via MITRE·09:10 AM
Data Sourced
via MITRE·09:10 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-2075 about?
CVE-2022-2075 refers to a Regex Denial of Service vulnerability in Octopus Deploy targeting the build information request validation.
2
How severe is CVE-2022-2075?
CVE-2022-2075 has a severity rating of 7.5, which is considered high.
3
Which versions of Octopus Deploy are affected by CVE-2022-2075?
Versions ranging from 0.9.0 to 4.1.10 of Octopus Deploy are affected by CVE-2022-2075.
4
Is Linux or Microsoft Windows affected by CVE-2022-2075?
No, Linux and Microsoft Windows are not affected by CVE-2022-2075.