CVE-2022-2782
27.10.2022, 10:15
In affected versions of Octopus Server it is possible for a session token to be valid indefinitely due to improper validation of the session token parameters.Enginsight
Vendor | Product | Version |
---|---|---|
octopus | octopus_server | 𝑥 < 2022.2.8351 |
octopus | octopus_server | 2022.3.0 ≤ 𝑥 < 2022.3.10586 |
octopus | octopus_server | 2022.4.0 ≤ 𝑥 < 2022.4.2898 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration