CVE-2022-2760

MEDIUM

Octopus Server 2019.5.7-2022.1.3180 - Information Disclosure via Error Message

Title source: llm
STIX 2.1

Description

In affected versions of Octopus Deploy it is possible to reveal the Space ID of spaces that the user does not have access to view in an error message when a resource is part of another Space.

References (1)

Core 1
Core References

Scores

CVSS v3 4.3
EPSS 0.0043
EPSS Percentile 34.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-209
Status published
Products (1)
octopus/octopus_server 2019.5.7 - 2022.1.3180
Published Sep 28, 2022
Tracked Since Feb 18, 2026