CVE-2022-3614: Medium severity octopus deploy vulnerability
Published Jan 3, 2023
·Updated
In affected versions of Octopus Deploy users of certain browsers using AD to sign-in to Octopus Server were able to bypass authentication checks and be redirected to the configured redirect url without any validation.
Affected Software
2 affected components
Octopus Octopus Server>=3.5<2022.3.10750
Octopus Octopus Server>=2022.4<2022.4.8063
Event History
Jan 3, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-3614?
CVE-2022-3614 has a severity rating of medium due to the potential for authentication bypass in affected versions.
2
How do I fix CVE-2022-3614?
To fix CVE-2022-3614, upgrade Octopus Deploy to version 2022.4.8064 or later.
3
Which versions of Octopus Deploy are affected by CVE-2022-3614?
CVE-2022-3614 affects Octopus Deploy versions from 3.5 up to 2022.3.10750 and from 2022.4 up to 2022.4.8063.
4
Can CVE-2022-3614 be exploited remotely?
Yes, CVE-2022-3614 can be exploited remotely if a user utilizes specific browsers to sign in.
5
What are the implications of CVE-2022-3614 for organizations?
Organizations using affected versions of Octopus Deploy may face unauthorized access risks due to bypassed authentication checks.