Cross-Site Scripting Vulnerability in Octopus Server by Octopus Deploy
CVE-2022-4898
5.4MEDIUM
What is CVE-2022-4898?
A Cross-Site Scripting vulnerability was discovered in Octopus Server, where the help sidebar could be manipulated to include harmful scripts in the support link. Although a fix was initially provided in advisory 2022-07, it was found that the solution could be bypassed under specific circumstances. Octopus Deploy has taken a new approach to ensure that the support link is no longer susceptible to such XSS attacks, enhancing the security posture of the affected version.
Affected Version(s)
Octopus Server 2019.7.0
Octopus Server < 2022.2.8552
Octopus Server 2022.3.348