First published: Fri Jul 15 2022(Updated: )
In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the support link.
Credit: security@octopus.com
Affected Software | Affected Version | How to fix |
---|---|---|
Octopus Octopus Server | >=2019.7.0<2021.3.13021 | |
Octopus Octopus Server | >=2022.1.2121<2022.1.2849 | |
Octopus Octopus Server | >=2022.3.348<2022.3.2387 | |
Octopus Octopus Server | =2022.2.6729 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-29890.
The severity of CVE-2022-29890 is medium with a severity value of 6.1.
In affected versions of Octopus Server, the help sidebar can be customized to include a Cross-Site Scripting payload in the support link.
Versions of Octopus Server from 2019.7.0 to 2021.3.13021 and from 2022.1.2121 to 2022.1.2849 are affected by CVE-2022-29890.
Upgrade to a version of Octopus Server that is not affected by CVE-2022-29890.