CVE-2022-4898: XSS
In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the support link. This was initially resolved in advisory 2022-07 however it was identified that the fix could be bypassed in certain circumstances. A different approach was taken to prevent the possibility of the support link being susceptible to XSS
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-4898 vulnerability?
CVE-2022-4898 vulnerability allows customization of the help sidebar in Octopus Server to include a Cross-Site Scripting payload in the support link, affecting certain versions of the software.
How to mitigate CVE-2022-4898?
To mitigate CVE-2022-4898, it is recommended to update Octopus Server to a non-vulnerable version as provided in the advisory.
What is the severity of CVE-2022-4898?
The severity of CVE-2022-4898 is rated as medium with a CVSS score of 5.4.