First published: Wed Aug 02 2023(Updated: )
In affected versions of Octopus Deploy it is possible for a low privileged guest user to craft a request that allows enumeration/recon of an environment.
Credit: security@octopus.com security@octopus.com
Affected Software | Affected Version | How to fix |
---|---|---|
Octopus Octopus Server | >=2019.4.0<2022.4.9997 | |
Octopus Octopus Server | >=2023.1.4189<2023.1.10235 | |
Octopus Octopus Server | >=2023.2.2028<2023.2.10545 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2416 is a vulnerability in Octopus Deploy that allows a low privileged guest user to craft a request for enumeration/recon of an environment.
The affected versions of Octopus Deploy are between 2019.4.0 to 2022.4.9997 and between 2023.1.4189 to 2023.2.10545.
The severity of CVE-2022-2416 is medium with a severity value of 4.3.
A low privileged guest user can exploit CVE-2022-2416 by crafting a request to perform enumeration and reconnaissance of an environment.
To fix CVE-2022-2416, update Octopus Deploy to a version that is not affected by the vulnerability.