CVE-2022-1502

EUVD-2022-24803
Permissions were not properly verified in the API on projects using version control in Git. This allowed projects to be modified by users with only ProjectView permissions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 38%
Affected Products (NVD)
VendorProductVersion
octopusserver
2021.3 ≤
𝑥
< 2021.3.12725
octopusserver
2022.1 ≤
𝑥
< 2022.1.2454
𝑥
= Vulnerable software versions