CVE-2022-4898
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the support link. This was initially resolved in advisory 2022-07 however it was identified that the fix could be bypassed in certain circumstances. A different approach was taken to prevent the possibility of the support link being susceptible to XSS
En las versiones afectadas de Octopus Server, la barra lateral de ayuda se puede personalizar para incluir un payload de Cross-Site Scripting en el enlace de soporte. Esto se resolvió inicialmente en el aviso 2022-07, sin embargo, se identificó que la solución podría omitirse en determinadas circunstancias. Se adoptó un enfoque diferente para evitar la posibilidad de que el enlace de soporte sea susceptible a XSS.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-01-30 CVE Reserved
- 2023-01-31 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-23 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://advisories.octopus.com/post/2022/sa2023-01 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Octopus Search vendor "Octopus" | Octopus Server Search vendor "Octopus" for product "Octopus Server" | >= 2019.7.0 < 2022.2.8552 Search vendor "Octopus" for product "Octopus Server" and version " >= 2019.7.0 < 2022.2.8552" | - |
Affected
| ||||||
Octopus Search vendor "Octopus" | Octopus Server Search vendor "Octopus" for product "Octopus Server" | >= 2022.3.348 < 2022.3.10750 Search vendor "Octopus" for product "Octopus Server" and version " >= 2022.3.348 < 2022.3.10750" | - |
Affected
| ||||||
Octopus Search vendor "Octopus" | Octopus Server Search vendor "Octopus" for product "Octopus Server" | >= 2022.4.791 < 2022.4.8319 Search vendor "Octopus" for product "Octopus Server" and version " >= 2022.4.791 < 2022.4.8319" | - |
Affected
|