CVE-2022-23184

In affected Octopus Server versions when the server HTTP and HTTPS bindings are configured to localhost, Octopus Server will allow open redirects.
Open Redirect
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
OctopusCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
VendorProductVersion
octopusoctopus_deploy
0.9 ≤
𝑥
≤ 4.1.10
octopusoctopus_deploy
2018.1.0 ≤
𝑥
≤ 2020.1.1
octopusoctopus_server
2021.2.0 ≤
𝑥
< 2021.2.8011
octopusoctopus_server
2021.3.0 ≤
𝑥
< 2021.3.11057
𝑥
= Vulnerable software versions