CVE-2022-2508
27.10.2022, 10:15
In affected versions of Octopus Server it is possible to reveal the existence of resources in a space that the user does not have access to due to verbose error messaging.Enginsight
Vendor | Product | Version |
---|---|---|
octopus | octopus_server | 𝑥 < 2022.1.3264 |
octopus | octopus_server | 2022.2.0 ≤ 𝑥 < 2022.2.8351 |
octopus | octopus_server | 2022.3.0 ≤ 𝑥 < 2022.3.10586 |
octopus | octopus_server | 2022.4.0 ≤ 𝑥 < 2022.4.2898 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration