CVE-2022-2720: Medium severity octopus deploy vulnerability
Published Oct 12, 2022
·Updated
In affected versions of Octopus Server it was identified that when a sensitive value is a substring of another value, sensitive value masking will only partially work.
Affected Software
3 affected components
Octopus Octopus Server>=3.16.4<2022.1.3154
Octopus Octopus Server>=2022.2.6729<2022.2.7934
Octopus Octopus Server>=2022.3.348<2022.3.10586
Event History
Oct 12, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-2720?
CVE-2022-2720 has been rated as a medium severity vulnerability.
2
How do I fix CVE-2022-2720?
To mitigate CVE-2022-2720, you should update to a patched version of Octopus Server that addresses this vulnerability.
3
What versions of Octopus Server are affected by CVE-2022-2720?
CVE-2022-2720 affects Octopus Server versions from 3.16.4 to 2022.1.3154, 2022.2.6729 to 2022.2.7934, and from 2022.3.348 to 2022.3.10586.
4
What kind of issue does CVE-2022-2720 expose?
CVE-2022-2720 exposes an issue where sensitive value masking is only partially effective when a sensitive value is a substring of another value.
5
Is CVE-2022-2720 a critical vulnerability?
No, CVE-2022-2720 is classified as medium severity, indicating it is not critical but still important to address.