CVE-2022-4009: Command Injection
Published Mar 16, 2023
·Updated
In affected versions of Octopus Deploy it is possible for a user to introduce code via offline package creation
Affected Software
3 affected components
Octopus Octopus Server>=3.0.19<2022.2.8552
Octopus Octopus Server>=2022.3.348<2022.3.10750
Octopus Octopus Server>=2022.4.791<2022.4.8319
Event History
Mar 16, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability CVE-2022-4009?
Vulnerability CVE-2022-4009 is a security flaw in Octopus Deploy that allows a user to introduce code via offline package creation.
2
How does vulnerability CVE-2022-4009 impact Octopus Deploy?
Vulnerability CVE-2022-4009 can be exploited by an attacker to inject malicious code into Octopus Deploy through offline package creation.
3
Which versions of Octopus Deploy are affected by vulnerability CVE-2022-4009?
Versions between 3.0.19 and 2022.2.8552, 2022.3.348 and 2022.3.10750, and 2022.4.791 and 2022.4.8319 of Octopus Deploy are affected by vulnerability CVE-2022-4009.
4
What is the severity of vulnerability CVE-2022-4009?
Vulnerability CVE-2022-4009 has a severity rating of 8.8 (high).
5
How can I fix vulnerability CVE-2022-4009 in Octopus Deploy?
To fix vulnerability CVE-2022-4009, it is recommended to update Octopus Deploy to a version that is not affected by the vulnerability.