← Back

CVE-2022-2074

nvd nist
Published: Aug 19, 2022Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service using the Variable Project Template.

Affected (12)

1 product
Octopus Server
Configuration A
12 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Octopus
From 0.9 to 0.9.620.4
From 1.0 to 1.6.3.1723
From 2.0 to 2.6.5
From 2018.1.0 to 2018.12.1
From 2019.1.0 to 2019.13.7
From 2020.1.0 to 2020.6.5449
From 2021.1.6959 to 2021.3.13021
From 2022.1.0 to 2022.1.2894
From 2022.2.6729 to 2022.2.6872
From 2022.3.348 to 2022.3.4953
From 3.0.0 to 3.17.14
From 4.0.4 to 4.1.10
Running on/withPlatform Versions
Linux
Linux Kernel
All versions
Microsoft
Windows
All versions

References (2)

Source: security@octopus.com
MitigationPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationPatchVendor Advisory

Timeline

No history available yet.