CVE-2022-2760
28.09.2022, 12:15
In affected versions of Octopus Deploy it is possible to reveal the Space ID of spaces that the user does not have access to view in an error message when a resource is part of another Space.Enginsight
Vendor | Product | Version |
---|---|---|
octopus | octopus_server | 2019.5.7 ≤ 𝑥 < 2022.1.3180 |
octopus | octopus_server | 2022.2.0 ≤ 𝑥 < 2022.2.7965 |
octopus | octopus_server | 2022.3.0 ≤ 𝑥 < 2022.3.10405 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration