CVE-2022-2528: Medium severity octopus deploy vulnerability
In affected versions of Octopus Deploy it is possible to upload a package to built-in feed with insufficient permissions after re-indexing packages.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2528?
CVE-2022-2528 has been classified with a medium severity level due to the potential for unauthorized package uploads.
How do I fix CVE-2022-2528?
To fix CVE-2022-2528, upgrade your Octopus Deploy server to a version that is not affected by this vulnerability.
What are the affected versions for CVE-2022-2528?
CVE-2022-2528 affects Octopus Deploy versions between 3.0.0 and 4.1.10, as well as various other versions within the specified ranges.
What impact does CVE-2022-2528 have on Octopus Deploy?
CVE-2022-2528 allows unauthorized users to upload packages to the built-in feed, potentially compromising application security.
Is CVE-2022-2528 a common vulnerability in Octopus Deploy?
While not widespread, CVE-2022-2528 is significant for users of affected Octopus Deploy versions due to its implications for access control.