PT-2022-18595 · Unknown · Octopus Server

Justin Steven

·

Published

2022-10-14

·

Updated

2022-10-19

·

CVE-2022-2780

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Octopus Server (affected versions not specified)
Description The issue allows an attacker to use the Git Connectivity test function on the VCS project to initiate an SMB request, potentially leading to an NTLM relay attack.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2022-2780

Affected Products

Octopus Server