CVE-2022-2780

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/10/2022
Last modified:
15/05/2025

Description

In affected versions of Octopus Server it is possible to use the Git Connectivity test function on the VCS project to initiate an SMB request resulting in the potential for an NTLM relay attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:* 2021.2.994 (including) 2022.1.3180 (excluding)
cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:* 2022.2.6729 (including) 2022.2.7965 (excluding)
cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:* 2022.3.348 (including) 2022.3.10586 (excluding)