CVE Vulnerabilities

CVE-2022-2074

Published: Aug 19, 2022 | Modified: Aug 20, 2022
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service using the Variable Project Template.

Affected Software

Name Vendor Start Version End Version
Octopus_server Octopus 0.9 (including) 0.9.620.4 (including)
Octopus_server Octopus 1.0 (including) 1.6.3.1723 (including)
Octopus_server Octopus 2.0 (including) 2.6.5 (including)
Octopus_server Octopus 3.0.0 (including) 3.17.14 (including)
Octopus_server Octopus 4.0.4 (including) 4.1.10 (including)
Octopus_server Octopus 2018.1.0 (including) 2018.12.1 (including)
Octopus_server Octopus 2019.1.0 (including) 2019.13.7 (including)
Octopus_server Octopus 2020.1.0 (including) 2020.6.5449 (including)
Octopus_server Octopus 2021.1.6959 (including) 2021.3.13021 (including)
Octopus_server Octopus 2022.1.0 (including) 2022.1.2894 (excluding)
Octopus_server Octopus 2022.2.6729 (including) 2022.2.6872 (excluding)
Octopus_server Octopus 2022.3.348 (including) 2022.3.4953 (excluding)

References