Cross-Site Scripting Vulnerability in Octopus Server by Octopus Deploy
CVE-2022-4898
5.4MEDIUM
What is CVE-2022-4898?
A Cross-Site Scripting vulnerability was discovered in Octopus Server, where the help sidebar could be manipulated to include harmful scripts in the support link. Although a fix was initially provided in advisory 2022-07, it was found that the solution could be bypassed under specific circumstances. Octopus Deploy has taken a new approach to ensure that the support link is no longer susceptible to such XSS attacks, enhancing the security posture of the affected version.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Octopus Server 2019.7.0
Octopus Server < 2022.2.8552
Octopus Server 2022.3.348
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
