Regex Denial of Service in Octopus Deploy by Octopus Deploy
CVE-2022-2049
7.5HIGH
What is CVE-2022-2049?
In certain versions of Octopus Deploy, a vulnerability exists that could allow attackers to execute a regex denial of service through the package upload feature. This flaw could potentially lead to service disruptions if exploited, highlighting the need for users to ensure their systems are updated to the latest secure release to mitigate risks.
Affected Version(s)
Octopus Server 0.9
Octopus Server < 2022.1.2894
Octopus Server 2022.2.6729