CVE-2022-2760
Octopus Deploy vulnerability analysis and mitigation

Overview

In affected versions of Octopus Deploy, a vulnerability (CVE-2022-2760) was discovered that allows the exposure of Space ID information through error messages. The vulnerability affects versions after 2019.5.7, including all 2020.x and 2021.x versions, 2022.1.x versions before 2022.1.3180, 2022.2.x versions before 2022.2.7965, and 2022.3.x versions before 2022.3.10586. The issue was discovered during internal testing by Scott Merchant at Octopus Deploy (Octopus Advisory).

Technical details

The vulnerability allows unauthorized users to view Space IDs of spaces they don't have access to when a resource is part of another Space. This information exposure occurs through error messages displayed by the system. The vulnerability has been assigned a low severity rating according to Octopus Deploy's severity levels (Octopus Advisory).

Impact

The impact of this vulnerability is limited to the exposure of Space ID information through error messages when users attempt to access resources in spaces they don't have permission to view. While this represents an information disclosure issue, the severity is considered low due to the limited nature of the exposed information (Octopus Advisory).

Mitigation and workarounds

The vulnerability has been fixed in versions 2022.1.3180, 2022.2.7965, and 2022.3.10586. Octopus Deploy recommends upgrading to the latest version (2022.3.10594). There are no known mitigations for this vulnerability other than upgrading to a fixed version (Octopus Advisory).

Additional resources


SourceThis report was generated using AI

Related Octopus Deploy vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-0539MEDIUM5.9
  • Octopus DeployOctopus Deploy
  • cpe:2.3:a:octopus:octopus_server
NoYesApr 10, 2025
CVE-2025-0588MEDIUM5.9
  • Octopus DeployOctopus Deploy
  • cpe:2.3:a:octopus:octopus_server
NoYesFeb 11, 2025
CVE-2025-0526LOW2.3
  • Octopus DeployOctopus Deploy
  • cpe:2.3:a:octopus:octopus_server
NoYesFeb 11, 2025
CVE-2025-0525LOW2.3
  • Octopus DeployOctopus Deploy
  • cpe:2.3:a:octopus:octopus_server
NoYesFeb 11, 2025
CVE-2025-0513LOW1.8
  • Octopus DeployOctopus Deploy
  • cpe:2.3:a:octopus:octopus_server
NoYesFeb 11, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management