CVE-2022-2528
09.09.2022, 08:15
In affected versions of Octopus Deploy it is possible to upload a package to built-in feed with insufficient permissions after re-indexing packages.Enginsight
Vendor | Product | Version |
---|---|---|
octopus | octopus_server | 3.0.0 ≤ 𝑥 ≤ 4.1.10 |
octopus | octopus_server | 2018.1.0 ≤ 𝑥 ≤ 2021.3.13021 |
octopus | octopus_server | 2022.1.0 ≤ 𝑥 < 2022.1.3106 |
octopus | octopus_server | 2022.2.6729 ≤ 𝑥 < 2022.2.7718 |
octopus | octopus_server | 2022.3.348 ≤ 𝑥 < 2022.3.7782 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration