First published: Wed Aug 02 2023(Updated: )
In affected versions of Octopus Deploy it is possible for a low privileged guest user to interact with extension endpoints.
Credit: security@octopus.com security@octopus.com
Affected Software | Affected Version | How to fix |
---|---|---|
Octopus Octopus Server | >=2019.4.0<2022.4.9997 | |
Octopus Octopus Server | >=2023.1.4189<2023.1.10235 | |
Octopus Octopus Server | >=2023.2.2028<2023.2.10545 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2346 is a vulnerability in Octopus Deploy that allows a low privileged guest user to interact with extension endpoints.
Affected versions of Octopus Deploy include 2019.4.0 up to 2022.4.9997, 2023.1.4189 up to 2023.1.10235, and 2023.2.2028 up to 2023.2.10545.
CVE-2022-2346 has a severity rating of 4.3, which is considered medium.
To fix CVE-2022-2346, you should upgrade to a non-affected version of Octopus Deploy.
You can find more information about CVE-2022-2346 in the advisory posted at https://advisories.octopus.com/post/2023/sa2023-10/