CVE-2022-29890: XSS
Published Jul 15, 2022
·Updated
In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the support link.
Affected Software
4 affected components
Octopus Octopus Server>=2019.7.0<2021.3.13021
Octopus Octopus Server>=2022.1.2121<2022.1.2849
Octopus Octopus Server>=2022.3.348<2022.3.2387
Octopus Octopus Server=2022.2.6729
Event History
Jul 15, 2022
CVE Published
via MITRE·07:40 AM
Data Sourced
via MITRE·07:40 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-29890.
2
What is the severity of CVE-2022-29890?
The severity of CVE-2022-29890 is medium with a severity value of 6.1.
3
How does CVE-2022-29890 affect Octopus Server?
In affected versions of Octopus Server, the help sidebar can be customized to include a Cross-Site Scripting payload in the support link.
4
Which versions of Octopus Server are affected by CVE-2022-29890?
Versions of Octopus Server from 2019.7.0 to 2021.3.13021 and from 2022.1.2121 to 2022.1.2849 are affected by CVE-2022-29890.
5
How can I fix CVE-2022-29890?
Upgrade to a version of Octopus Server that is not affected by CVE-2022-29890.