First published: Wed Oct 12 2022(Updated: )
In affected versions of Octopus Server it was identified that when a sensitive value is a substring of another value, sensitive value masking will only partially work.
Credit: security@octopus.com
Affected Software | Affected Version | How to fix |
---|---|---|
Octopus Deploy | >=3.16.4<2022.1.3154 | |
Octopus Deploy | >=2022.2.6729<2022.2.7934 | |
Octopus Deploy | >=2022.3.348<2022.3.10586 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2720 has been rated as a medium severity vulnerability.
To mitigate CVE-2022-2720, you should update to a patched version of Octopus Server that addresses this vulnerability.
CVE-2022-2720 affects Octopus Server versions from 3.16.4 to 2022.1.3154, 2022.2.6729 to 2022.2.7934, and from 2022.3.348 to 2022.3.10586.
CVE-2022-2720 exposes an issue where sensitive value masking is only partially effective when a sensitive value is a substring of another value.
No, CVE-2022-2720 is classified as medium severity, indicating it is not critical but still important to address.