CVE-2022-2780: High severity octopus deploy vulnerability
Published Oct 14, 2022
·Updated
In affected versions of Octopus Server it is possible to use the Git Connectivity test function on the VCS project to initiate an SMB request resulting in the potential for an NTLM relay attack.
Affected Software
3 affected components
Octopus Octopus Server>=2021.2.994<2022.1.3180
Octopus Octopus Server>=2022.2.6729<2022.2.7965
Octopus Octopus Server>=2022.3.348<2022.3.10586
Event History
Oct 14, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-2780?
CVE-2022-2780 is classified as a high severity vulnerability due to its potential for NTLM relay attacks.
2
How do I fix CVE-2022-2780?
To fix CVE-2022-2780, upgrade to a version of Octopus Server that is not affected by this vulnerability.
3
Which versions of Octopus Server are affected by CVE-2022-2780?
CVE-2022-2780 affects Octopus Server versions between 2021.2.994 to 2022.1.3180, 2022.2.6729 to 2022.2.7965, and 2022.3.348 to 2022.3.10586.
4
What types of attacks can CVE-2022-2780 facilitate?
CVE-2022-2780 can facilitate NTLM relay attacks through improper handling of SMB requests.
5
Is there a workaround for CVE-2022-2780?
There are no known effective workarounds for CVE-2022-2780; upgrading is the recommended solution.