First published: Thu Oct 27 2022(Updated: )
In affected versions of Octopus Server it is possible to reveal the existence of resources in a space that the user does not have access to due to verbose error messaging.
Credit: security@octopus.com
Affected Software | Affected Version | How to fix |
---|---|---|
Octopus Deploy | <2022.1.3264 | |
Octopus Deploy | >=2022.2.0<2022.2.8351 | |
Octopus Deploy | >=2022.3.0<2022.3.10586 | |
Octopus Deploy | >=2022.4.0<2022.4.2898 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2508 is classified as a medium severity vulnerability due to information disclosure risks.
To mitigate CVE-2022-2508, you should upgrade to Octopus Server version 2022.1.3264 or later.
CVE-2022-2508 affects Octopus Server versions prior to 2022.1.3264, as well as certain versions between 2022.2.0 and 2022.4.2898.
CVE-2022-2508 is an information disclosure vulnerability that allows users to see resources they do not have access to.
Users of Octopus Server who are on affected versions are at risk of this vulnerability.