CVE-2022-2258: Medium severity octopus deploy vulnerability
In affected versions of Octopus Deploy it is possible for a user to view Tagsets without being explicitly assigned permissions to view these items
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2258?
CVE-2022-2258 has a medium severity rating due to the improper handling of permissions allowing unauthorized access to Tagsets.
How do I fix CVE-2022-2258?
To remediate CVE-2022-2258, update Octopus Deploy to a version beyond 2022.3.11098, 2022.4.791 through 2022.4.8463, or 2023.1.4189 through 2023.1.9672.
What types of software are affected by CVE-2022-2258?
CVE-2022-2258 affects several versions of Octopus Deploy Server, including those from 2019.1.0 up to 2023.1.9672 and specific version 2023.2.2028.
Who is impacted by CVE-2022-2258?
Users of Octopus Deploy versions as specified in CVE-2022-2258 may be impacted if they have not been assigned permissions to view Tagsets.
Is there a workaround for CVE-2022-2258?
There are currently no known workarounds for CVE-2022-2258; the only solution is to upgrade to a patched version.