CVE-2024-4226
30.04.2024, 02:15
It was identified that in certain versions of Octopus Server, that a user created with no permissions could view all users, user roles and permissions. This functionality was removed in versions of Octopus Server after the fixed versions listed.Enginsight
Vendor | Product | Version |
---|---|---|
octopus | octopus_server | 2022.2.6729 ≤ 𝑥 < 2022.2.7934 |
octopus | octopus_server | 2022.3.348 ≤ 𝑥 < 2022.3.9163 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration