Access Control Vulnerability in Octopus Deploy
CVE-2022-2259
4.3MEDIUM
What is CVE-2022-2259?
A vulnerability exists in certain versions of Octopus Deploy that allows unauthorized users to view Workerpools without having the necessary permissions. This flaw can lead to sensitive information exposure, potentially compromising the security of deployments.
Affected Version(s)
Octopus Server 2019.1.0
Octopus Server < 2022.3.11098
Octopus Server 2022.4.791