CVE-2022-1670
19.05.2022, 05:15
When generating a user invitation code in Octopus Server, the validity of this code can be set for a specific number of users. It was possible to bypass this restriction of validity to create extra user accounts above the initial number of invited users.Enginsight
Vendor | Product | Version |
---|---|---|
octopus | octopus_server | 0.9 ≤ 𝑥 < 2021.3.12533 |
octopus | octopus_server | 2022.1.0 ≤ 𝑥 < 2022.1.53 |
𝑥
= Vulnerable software versions