6.1
CVE-2022-23184
- EPSS 0.19%
- Veröffentlicht 07.02.2022 03:15:07
- Zuletzt bearbeitet 21.11.2024 06:48:09
- Quelle security@octopus.com
- CVE-Watchlists
- Unerledigt
In affected Octopus Server versions when the server HTTP and HTTPS bindings are configured to localhost, Octopus Server will allow open redirects.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Octopus ≫ Octopus Deploy Version >= 0.9 <= 4.1.10
Octopus ≫ Octopus Deploy Version >= 2018.1.0 <= 2020.1.1
Octopus ≫ Octopus Server Version >= 2021.2.0 < 2021.2.8011
Octopus ≫ Octopus Server Version >= 2021.3.0 < 2021.3.11057
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.371 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
| nvd@nist.gov | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.