In affected Octopus Server versions when the server HTTP and HTTPS bindings are configured to localhost, Octopus Server will allow open redirects.
References
Link Resource
https://advisories.octopus.com/post/2022/sa2022-02/ Mitigation Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Octopus

Published: 2022-02-07T02:35:09

Updated: 2022-02-07T02:35:09

Reserved: 2022-01-12T00:00:00


Link: CVE-2022-23184

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-02-07T03:15:07.427

Modified: 2022-07-27T16:57:43.070


Link: CVE-2022-23184

JSON object: View

cve-icon Redhat Information

No data.

CWE