CVE-2022-1881
15.07.2022, 08:15
In affected versions of Octopus Server an Insecure Direct Object Reference vulnerability exists where it is possible for a user to download Project Exports from a Project they do not have permissions to access. This vulnerability only impacts projects within the same Space.Enginsight
Vendor | Product | Version |
---|---|---|
octopus | octopus_server | 2021.1.6959 ≤ 𝑥 < 2021.3.13021 |
octopus | octopus_server | 2022.1.2121 ≤ 𝑥 < 2022.1.2894 |
octopus | octopus_server | 2022.2.6729 ≤ 𝑥 < 2022.2.6971 |
octopus | octopus_server | 2022.3.348 ≤ 𝑥 < 2022.3.2616 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration