« Volver al listado

CVE-2022-29890

Estado: ModificadaMedia (6.1)—

In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the support link.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-29890",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@octopus.com",
      "affectedData": [
        {
          "vendor": "Octopus Deploy",
          "product": "Octopus Server",
          "versions": [
            {
              "status": "affected",
              "version": "2019.7.0",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "2021.3.13021",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "2022.1.2121",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "2022.1.2894",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "2022.2.6729",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "2022.2.6971",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "2022.3.348",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "2022.3.2387",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-07-15T08:15:07.557",
  "references": [
    {
      "url": "https://advisories.octopus.com/post/2022/sa2022-07/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@octopus.com"
    },
    {
      "url": "https://advisories.octopus.com/post/2022/sa2022-07/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the support link."
    },
    {
      "lang": "es",
      "value": "En las versiones afectadas de Octopus Server la barra lateral de ayuda puede ser personalizada para incluir una carga útil de tipo Cross-Site Scripting en el enlace de soporte"
    }
  ],
  "lastModified": "2026-06-17T04:40:54.820",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FC629667-50EC-4AFC-8E90-6C070AD060B7",
              "versionEndExcluding": "2021.3.13021",
              "versionStartIncluding": "2019.7.0"
            },
            {
              "criteria": "cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C74436F7-62F5-4F14-9B36-754B11F62D37",
              "versionEndExcluding": "2022.1.2849",
              "versionStartIncluding": "2022.1.2121"
            },
            {
              "criteria": "cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6F8976F6-C318-48BE-BC03-788FB43C3C95",
              "versionEndExcluding": "2022.3.2387",
              "versionStartIncluding": "2022.3.348"
            },
            {
              "criteria": "cpe:2.3:a:octopus:octopus_server:2022.2.6729:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A5547FBE-BDAE-4666-92A7-F883022F6570"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@octopus.com"
}