CVE-2022-2780

HIGH

Octopus Server - SSRF

Title source: llm

Description

In affected versions of Octopus Server it is possible to use the Git Connectivity test function on the VCS project to initiate an SMB request resulting in the potential for an NTLM relay attack.

Scores

CVSS v3 8.1
EPSS 0.0041
EPSS Percentile 60.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-294
Status published

Affected Products (1)

octopus/octopus_server < 2022.1.3180

Timeline

Published Oct 14, 2022
Tracked Since Feb 18, 2026