NA

CVE-2022-2572

Published: 01/11/2022 Updated: 01/11/2022
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

In affected versions of Octopus Server where access is managed by an external authentication provider, it was possible that the API key/keys of a disabled/deleted user were still valid after the access was revoked.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

octopus octopus server