CVE-2022-2781
06.10.2022, 18:15
In affected versions of Octopus Server it was identified that the same encryption process was used for both encrypting session cookies and variables.Enginsight
Vendor | Product | Version |
---|---|---|
octopus | octopus_server | 3.2.10 ≤ 𝑥 < 2022.1.3154 |
octopus | octopus_server | 2022.2.6729 ≤ 𝑥 < 2022.2.7897 |
octopus | octopus_server | 2022.3.348 ≤ 𝑥 < 2022.3.10586 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration