In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Octopus_server | Octopus | 3.0 (including) | 2022.2.8277 (excluding) |
Octopus_server | Octopus | 2022.3.348 (including) | 2022.3.10405 (excluding) |
Octopus_server | Octopus | 2022.4.791 (including) | 2022.4.1371 (excluding) |