CVE-2022-2828

EUVD-2022-35064
In affected versions of Octopus Server it is possible to reveal information about teams via the API due to an Insecure Direct Object Reference (IDOR) vulnerability
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA-ADPADP
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 49%
Affected Products (NVD)
VendorProductVersion
octopusoctopus_server
2022.1.2121 ≤
𝑥
≤ 2022.1.3135
octopusoctopus_server
2022.2.0 ≤
𝑥
≤ 2022.2.7897
octopusoctopus_server
2022.3.0 ≤
𝑥
≤ 2022.3.10586
𝑥
= Vulnerable software versions