CVE-2022-2507: XSS
Published Apr 19, 2023
·Updated
In affected versions of Octopus Deploy it is possible to render user supplied input into the webpage
Affected Software
3 affected components
Octopus Octopus Server<2023.1.9794
Octopus Octopus Server>=2022.4.0<2022.4.8332
Octopus Octopus Server>=2023.1.0<2023.1.6715
Event History
Apr 19, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-2507?
CVE-2022-2507 has been rated as a medium severity vulnerability.
2
How do I fix CVE-2022-2507?
To fix CVE-2022-2507, update your Octopus Deploy installation to a version that is not affected, specifically above version 2023.1.9794 or within the secure ranges for other versions.
3
What versions of Octopus Deploy are affected by CVE-2022-2507?
CVE-2022-2507 affects versions of Octopus Deploy between 2022.4.0 and 2022.4.8332, as well as 2023.1.0 to 2023.1.6715.
4
What type of vulnerability is CVE-2022-2507?
CVE-2022-2507 is a cross-site scripting (XSS) vulnerability that allows for user-supplied input rendering in the webpage.
5
Is CVE-2022-2507 exploitable?
Yes, CVE-2022-2507 is exploitable if an attacker can provide malicious input that is rendered by the application.