CVE-2022-2780

HIGH

Octopus Server 2021.2.994-2022.1.3180 - NTLM Relay Attack via Git Connectivity Test

Title source: llm
STIX 2.1

Description

In affected versions of Octopus Server it is possible to use the Git Connectivity test function on the VCS project to initiate an SMB request resulting in the potential for an NTLM relay attack.

References (1)

Core 1
Core References

Scores

CVSS v3 8.1
EPSS 0.0051
EPSS Percentile 39.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-294
Status published
Products (1)
octopus/octopus_server 2021.2.994 - 2022.1.3180
Published Oct 14, 2022
Tracked Since Feb 18, 2026