CVE Vulnerabilities

CVE-2022-2778

Published: Sep 30, 2022 | Modified: May 20, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes.

Affected Software

NameVendorStart VersionEnd Version
Octopus_serverOctopus3.0 (including)2022.2.8277 (excluding)
Octopus_serverOctopus2022.3.348 (including)2022.3.10405 (excluding)
Octopus_serverOctopus2022.4.791 (including)2022.4.1371 (excluding)

References