CVE Vulnerabilities

CVE-2022-1901

Improper Privilege Management

Published: Aug 19, 2022 | Modified: Aug 08, 2023
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In affected versions of Octopus Deploy it is possible to unmask sensitive variables by using variable preview.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Octopus_server Octopus 2019.1.0 (including) 2019.7.3 (including)
Octopus_server Octopus 2020.1.0 (including) 2020.6.5449 (including)
Octopus_server Octopus 2021.1.6959 (including) 2021.3.13021 (including)
Octopus_server Octopus 2022.1.0 (including) 2022.1.3009 (excluding)
Octopus_server Octopus 2022.2.6729 (including) 2022.2.7244 (excluding)
Octopus_server Octopus 2022.3.348 (including) 2022.3.4953 (excluding)

Potential Mitigations

References