← Back

CVE-2022-2760

nvd nist
Published: Sep 28, 2022Modified: Jun 17, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

In affected versions of Octopus Deploy it is possible to reveal the Space ID of spaces that the user does not have access to view in an error message when a resource is part of another Space.

Affected (3)

1 product
Octopus Server
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Octopus
From 2019.5.7 to 2022.1.3180
From 2022.2.0 to 2022.2.7965
From 2022.3.0 to 2022.3.10405

References (2)

Source: security@octopus.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.