CVE-2022-2416: SSRF
Published Aug 2, 2023
·Updated
In affected versions of Octopus Deploy it is possible for a low privileged guest user to craft a request that allows enumeration/recon of an environment.
Affected Software
3 affected components
Octopus Octopus Server>=2019.4.0<2022.4.9997
Octopus Octopus Server>=2023.1.4189<2023.1.10235
Octopus Octopus Server>=2023.2.2028<2023.2.10545
Event History
Aug 2, 2023
CVE Published
via MITRE·05:26 AM
Data Sourced
via MITRE·05:26 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-2416?
CVE-2022-2416 is a vulnerability in Octopus Deploy that allows a low privileged guest user to craft a request for enumeration/recon of an environment.
2
Which versions of Octopus Deploy are affected by CVE-2022-2416?
The affected versions of Octopus Deploy are between 2019.4.0 to 2022.4.9997 and between 2023.1.4189 to 2023.2.10545.
3
What is the severity of CVE-2022-2416?
The severity of CVE-2022-2416 is medium with a severity value of 4.3.
4
How can a low privileged guest user exploit CVE-2022-2416?
A low privileged guest user can exploit CVE-2022-2416 by crafting a request to perform enumeration and reconnaissance of an environment.
5
How can I fix CVE-2022-2416 in Octopus Deploy?
To fix CVE-2022-2416, update Octopus Deploy to a version that is not affected by the vulnerability.