CVE-2022-2013

In Octopus Server after version 2022.1.1495 and before 2022.1.2647 if private spaces were enabled via the experimental feature flag all new users would have access to the Script Console within their private space.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:octopus:octopus_deploy:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

17 Jun 2022, 19:09

Type Values Removed Values Added
References (MISC) https://advisories.octopus.com/post/2022/sa2022-05/ - (MISC) https://advisories.octopus.com/post/2022/sa2022-05/ - Vendor Advisory
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:octopus:octopus_deploy:*:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
First Time Linux
Microsoft
Microsoft windows
Octopus octopus Deploy
Linux linux Kernel
Octopus
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 7.5

13 Jun 2022, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-06-13 00:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-2013

Mitre link : CVE-2022-2013

CVE.ORG link : CVE-2022-2013


JSON object : View

Products Affected

linux

  • linux_kernel

microsoft

  • windows

octopus

  • octopus_deploy