CVE-2022-2883

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
22/02/2023
Last modified:
11/03/2025

Description

In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:* 2022.3.11043 (excluding)
cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:* 2022.4.0 (including) 2022.4.8401 (excluding)