CVE-2022-2780
HIGHOctopus Server - SSRF
Title source: llmDescription
In affected versions of Octopus Server it is possible to use the Git Connectivity test function on the VCS project to initiate an SMB request resulting in the potential for an NTLM relay attack.
Scores
CVSS v3
8.1
EPSS
0.0041
EPSS Percentile
60.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-294
Status
published
Affected Products (1)
octopus/octopus_server
< 2022.1.3180
Timeline
Published
Oct 14, 2022
Tracked Since
Feb 18, 2026