CVE-2022-2828

In affected versions of Octopus Server it is possible to reveal information about teams via the API due to an Insecure Direct Object Reference (IDOR) vulnerability
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
OctopusCNA
---
---
CVEADP
---
---
CISA-ADPADP
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 35%
VendorProductVersion
octopusoctopus_server
2022.1.2121 ≤
𝑥
≤ 2022.1.3135
octopusoctopus_server
2022.2.0 ≤
𝑥
≤ 2022.2.7897
octopusoctopus_server
2022.3.0 ≤
𝑥
≤ 2022.3.10586
𝑥
= Vulnerable software versions