CVE-2022-2778

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
30/09/2022
Last modified:
20/05/2025

Description

In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:* 3.0 (including) 2022.2.8277 (excluding)
cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:* 2022.3.348 (including) 2022.3.10405 (excluding)
cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:* 2022.4.791 (including) 2022.4.1371 (excluding)
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*