CVE-2022-2346: Medium severity octopus deploy vulnerability
Published Aug 2, 2023
·Updated
In affected versions of Octopus Deploy it is possible for a low privileged guest user to interact with extension endpoints.
Affected Software
3 affected components
Octopus Octopus Server>=2019.4.0<2022.4.9997
Octopus Octopus Server>=2023.1.4189<2023.1.10235
Octopus Octopus Server>=2023.2.2028<2023.2.10545
Event History
Aug 2, 2023
CVE Published
via MITRE·01:09 AM
Data Sourced
via MITRE·01:09 AM
DescriptionSeverityWeakness
Data Sourced
02:15 AM
Description
Frequently Asked Questions
1
What is CVE-2022-2346?
CVE-2022-2346 is a vulnerability in Octopus Deploy that allows a low privileged guest user to interact with extension endpoints.
2
Which versions of Octopus Deploy are affected by CVE-2022-2346?
Affected versions of Octopus Deploy include 2019.4.0 up to 2022.4.9997, 2023.1.4189 up to 2023.1.10235, and 2023.2.2028 up to 2023.2.10545.
3
How severe is CVE-2022-2346?
CVE-2022-2346 has a severity rating of 4.3, which is considered medium.
4
How can I fix CVE-2022-2346?
To fix CVE-2022-2346, you should upgrade to a non-affected version of Octopus Deploy.
5
Where can I find more information about CVE-2022-2346?
You can find more information about CVE-2022-2346 in the advisory posted at https://advisories.octopus.com/post/2023/sa2023-10/