Back to search
CVE-2022-4898
Published: Jan 31, 2023
Modified: Mar 27, 2025
PUBLISHED
Description
In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the support link. This was initially resolved in advisory 2022-07 however it was identified that the fix could be bypassed in certain circumstances. A different approach was taken to prevent the possibility of the support link being susceptible to XSS
| Vendor | Product | Versions |
|---|---|---|
Octopus Deploy | Octopus Server | affected 2019.7.0 - < unspecifiedaffected unspecified - < 2022.2.8552affected 2022.3.348 - < unspecifiedaffected unspecified - < 2022.3.10750affected 2022.4.791 - < unspecified+1 more versions |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now