CVE-2022-2259: Medium severity octopus deploy vulnerability
Published Mar 13, 2023
·Updated
In affected versions of Octopus Deploy it is possible for a user to view Workerpools without being explicitly assigned permissions to view these items
Affected Software
4 affected components
Octopus Octopus Server>=2019.1.0<2022.3.11098
Octopus Octopus Server>=2022.4.791<2022.4.8463
Octopus Octopus Server>=2023.1.4189<2023.1.9672
Octopus Octopus Server=2023.2.2028
Event History
Mar 13, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-2259?
The severity of CVE-2022-2259 is medium with a CVSS score of 4.3.
2
How does CVE-2022-2259 impact Octopus Deploy?
CVE-2022-2259 allows users to view Workerpools without having the necessary permissions.
3
Which versions of Octopus Deploy are affected by CVE-2022-2259?
Versions between 2019.1.0 and 2022.3.11098, and versions between 2022.4.791 and 2022.4.8463 of Octopus Deploy are affected by CVE-2022-2259.
4
How can I fix CVE-2022-2259 in Octopus Deploy?
To fix CVE-2022-2259, upgrade Octopus Deploy to version 2022.4.8463 or later.
5
Where can I find more information about CVE-2022-2259?
You can find more information about CVE-2022-2259 in the advisory posted on the Octopus Deploy website: https://advisories.octopus.com/post/2023/sa2023-04/