CVE-2022-2013
Last modified
CVE-2022-2013 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. In Octopus Server after version 2022.1.1495 and before 2022.1.2647 if private spaces were enabled via the experimental feature flag all new users would have access to the Script Console within their private space.. EPSS estimates a 0.83% chance of exploitation in the next 30 days.
Description
In Octopus Server after version 2022.1.1495 and before 2022.1.2647 if private spaces were enabled via the experimental feature flag all new users would have access to the Script Console within their private space.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Octopus | Octopus Deploy | >= 2022.1.1495, < 2022.1.2647 |
References
- https://advisories.octopus.com/post/2022/sa2022-05/Vendor Advisory
- https://advisories.octopus.com/post/2022/sa2022-05/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-2013?
How severe is CVE-2022-2013?
How do I fix CVE-2022-2013?
Are you affected by CVE-2022-2013?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
