CVE-2022-2075
19.08.2022, 09:15
In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service targeting the build information request validation.Enginsight
Vendor | Product | Version |
---|---|---|
octopus | octopus_server | 0.9 ≤ 𝑥 ≤ 0.9.620.4 |
octopus | octopus_server | 1.0 ≤ 𝑥 ≤ 1.6.3.1723 |
octopus | octopus_server | 2.0 ≤ 𝑥 ≤ 2.6.5 |
octopus | octopus_server | 3.0.0 ≤ 𝑥 ≤ 3.17.14 |
octopus | octopus_server | 4.0.4 ≤ 𝑥 ≤ 4.1.10 |
octopus | octopus_server | 2018.1.0 ≤ 𝑥 ≤ 2018.12.1 |
octopus | octopus_server | 2019.1.0 ≤ 𝑥 ≤ 2019.13.7 |
octopus | octopus_server | 2020.1.0 ≤ 𝑥 ≤ 2020.6.5449 |
octopus | octopus_server | 2021.1.6959 ≤ 𝑥 ≤ 2021.3.13021 |
octopus | octopus_server | 2022.1.0 ≤ 𝑥 < 2022.1.2894 |
octopus | octopus_server | 2022.2.6729 ≤ 𝑥 < 2022.2.6872 |
octopus | octopus_server | 2022.3.348 ≤ 𝑥 < 2022.3.4953 |
𝑥
= Vulnerable software versions