Cross-Site Scripting Vulnerability in Octopus Server by Octopus Deploy
CVE-2022-4898

5.4MEDIUM

Key Information:

Vendor
CVE Published:
31 January 2023

What is CVE-2022-4898?

A Cross-Site Scripting vulnerability was discovered in Octopus Server, where the help sidebar could be manipulated to include harmful scripts in the support link. Although a fix was initially provided in advisory 2022-07, it was found that the solution could be bypassed under specific circumstances. Octopus Deploy has taken a new approach to ensure that the support link is no longer susceptible to such XSS attacks, enhancing the security posture of the affected version.

Affected Version(s)

Octopus Server 2019.7.0

Octopus Server < 2022.2.8552

Octopus Server 2022.3.348

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.