CVE-2022-4870: Medium severity octopus deploy vulnerability
Published May 18, 2023
·Updated
In affected versions of Octopus Deploy it is possible to discover network details via error message
Affected Software
2 affected components
Octopus Octopus Server>=3.0.0<2023.1.9879
Octopus Octopus Server>=2023.2.2028<2023.2.8159
Event History
May 18, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-4870?
The severity of CVE-2022-4870 is classified as moderate due to potential information disclosure risks.
2
How do I fix CVE-2022-4870?
To fix CVE-2022-4870, upgrade Octopus Deploy to a version beyond 2023.1.9879 or after 2023.2.2028.
3
What types of network details can be exposed in CVE-2022-4870?
CVE-2022-4870 can expose sensitive network configuration details through error messages.
4
Which versions of Octopus Deploy are affected by CVE-2022-4870?
CVE-2022-4870 affects Octopus Deploy versions from 3.0.0 up to 2023.1.9879 and from 2023.2.2028 to 2023.2.8159.
5
Is CVE-2022-4870 an issue that can lead to further vulnerabilities?
Yes, the information disclosure in CVE-2022-4870 could potentially lead to further attacks if network details are exploited.