CVE-2022-2780

HIGH

Octopus Server - SSRF

Title source: llm
STIX 2.1

Description

In affected versions of Octopus Server it is possible to use the Git Connectivity test function on the VCS project to initiate an SMB request resulting in the potential for an NTLM relay attack.

Scores

CVSS v3 8.1
EPSS 0.0041
EPSS Percentile 61.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-294
Status published
Products (1)
octopus/octopus_server 2021.2.994 - 2022.1.3180
Published Oct 14, 2022
Tracked Since Feb 18, 2026