CVE-2022-2721: High severity octopus deploy vulnerability
In affected versions of Octopus Server it is possible for target discovery to print certain values marked as sensitive to log files in plaint-text in when verbose logging is enabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2721?
CVE-2022-2721 has been classified with a medium severity level due to the potential exposure of sensitive information through log files.
How do I fix CVE-2022-2721?
To fix CVE-2022-2721, you should upgrade to Octopus Server version 2022.2.7966 or later, or 2022.3.9164 or later.
What versions of Octopus Server are affected by CVE-2022-2721?
CVE-2022-2721 affects Octopus Server versions from 2022.2.6729 to 2022.2.7965 and 2022.3.348 to 2022.3.9163.
What type of information could be exposed due to CVE-2022-2721?
CVE-2022-2721 may expose sensitive values logged in plaintext when verbose logging is enabled during target discovery.
How can I prevent data exposure in logs related to CVE-2022-2721?
To prevent data exposure in logs related to CVE-2022-2721, avoid enabling verbose logging unless necessary and ensure you are on the latest version of Octopus Server.