CVE-2022-2778
30.09.2022, 04:15
In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes.Enginsight
Vendor | Product | Version |
---|---|---|
octopus | octopus_server | 3.0 ≤ 𝑥 < 2022.2.8277 |
octopus | octopus_server | 2022.3.348 ≤ 𝑥 < 2022.3.10405 |
octopus | octopus_server | 2022.4.791 ≤ 𝑥 < 2022.4.1371 |
𝑥
= Vulnerable software versions