Access Control Flaw in Octopus Server Affecting User Privileges
CVE-2022-2013

7.5HIGH

Key Information:

Vendor
CVE Published:
13 June 2022

What is CVE-2022-2013?

In Octopus Server, private spaces enabled via the experimental feature flag could lead to a situation where all new users automatically gain access to the Script Console within their private spaces. This vulnerability allows unauthorized users to execute scripts and potentially manipulate server functions, posing a significant risk to the integrity of projects and data managed within the server.

Affected Version(s)

Octopus Server 2022.1.1495

Octopus Server < 2022.1.2647

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.