Cross-Site Scripting Vulnerability in Octopus Server by Octopus Deploy
CVE-2022-4898

5.4MEDIUM

Key Information:

Vendor
CVE Published:
31 January 2023

What is CVE-2022-4898?

A Cross-Site Scripting vulnerability was discovered in Octopus Server, where the help sidebar could be manipulated to include harmful scripts in the support link. Although a fix was initially provided in advisory 2022-07, it was found that the solution could be bypassed under specific circumstances. Octopus Deploy has taken a new approach to ensure that the support link is no longer susceptible to such XSS attacks, enhancing the security posture of the affected version.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Octopus Server 2019.7.0

Octopus Server < 2022.2.8552

Octopus Server 2022.3.348

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.