First published: Thu Mar 16 2023(Updated: )
In affected versions of Octopus Deploy it is possible for a user to introduce code via offline package creation
Credit: security@octopus.com
Affected Software | Affected Version | How to fix |
---|---|---|
Octopus Deploy | >=3.0.19<2022.2.8552 | |
Octopus Deploy | >=2022.3.348<2022.3.10750 | |
Octopus Deploy | >=2022.4.791<2022.4.8319 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Vulnerability CVE-2022-4009 is a security flaw in Octopus Deploy that allows a user to introduce code via offline package creation.
Vulnerability CVE-2022-4009 can be exploited by an attacker to inject malicious code into Octopus Deploy through offline package creation.
Versions between 3.0.19 and 2022.2.8552, 2022.3.348 and 2022.3.10750, and 2022.4.791 and 2022.4.8319 of Octopus Deploy are affected by vulnerability CVE-2022-4009.
Vulnerability CVE-2022-4009 has a severity rating of 8.8 (high).
To fix vulnerability CVE-2022-4009, it is recommended to update Octopus Deploy to a version that is not affected by the vulnerability.