CVE-2022-2013

In Octopus Server after version 2022.1.1495 and before 2022.1.2647 if private spaces were enabled via the experimental feature flag all new users would have access to the Script Console within their private space.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:octopus:octopus_deploy:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:00

Type Values Removed Values Added
References () https://advisories.octopus.com/post/2022/sa2022-05/ - Vendor Advisory () https://advisories.octopus.com/post/2022/sa2022-05/ - Vendor Advisory

Information

Published : 2022-06-13 00:15

Updated : 2024-11-21 07:00


NVD link : CVE-2022-2013

Mitre link : CVE-2022-2013

CVE.ORG link : CVE-2022-2013


JSON object : View

Products Affected

linux

  • linux_kernel

microsoft

  • windows

octopus

  • octopus_deploy