CVE-2022-2572: Critical severity octopus deploy vulnerability
In affected versions of Octopus Server where access is managed by an external authentication provider, it was possible that the API key/keys of a disabled/deleted user were still valid after the access was revoked.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2572?
CVE-2022-2572 is considered a medium-severity vulnerability as it allows API keys of disabled or deleted users to remain valid.
How do I fix CVE-2022-2572?
To fix CVE-2022-2572, update Octopus Server to a version that addresses this issue, specifically versions after 2022.4.791.
Which versions of Octopus Server are affected by CVE-2022-2572?
CVE-2022-2572 affects Octopus Server versions from 3.5 up to 2022.4.791.
What are the risks associated with CVE-2022-2572?
The risks of CVE-2022-2572 include unauthorized access if API keys of disabled or deleted users remain operational.
Who does CVE-2022-2572 impact?
CVE-2022-2572 impacts organizations using Octopus Server with external authentication providers that enable automated key management.