Guest User Interaction Vulnerability in Octopus Deploy by Octopus Deploy
CVE-2022-2346
What is CVE-2022-2346?
In specific versions of Octopus Deploy, a security flaw exists that permits a low privileged guest user to interact with extension endpoints. This vulnerability potentially exposes sensitive information and functionalities that should be restricted, leading to unauthorized access or manipulation by unprivileged users. Organizations utilizing Octopus Deploy should ensure they are using updated versions to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Octopus Server Windows 2019.4.0 < 2022.4.9997
Octopus Server Windows 2023.1.0 < 2023.1.10235
Octopus Server Windows 2023.2.0 < 2023.2.10545
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
