CVE-2022-2828
13.10.2022, 05:15
In affected versions of Octopus Server it is possible to reveal information about teams via the API due to an Insecure Direct Object Reference (IDOR) vulnerabilityEnginsight
Vendor | Product | Version |
---|---|---|
octopus | octopus_server | 2022.1.2121 ≤ 𝑥 ≤ 2022.1.3135 |
octopus | octopus_server | 2022.2.0 ≤ 𝑥 ≤ 2022.2.7897 |
octopus | octopus_server | 2022.3.0 ≤ 𝑥 ≤ 2022.3.10586 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration