In affected versions of Octopus Server an Insecure Direct Object Reference vulnerability exists where it is possible for a user to download Project Exports from a Project they do not have permissions to access. This vulnerability only impacts projects within the same Space.
2022-07-15T08:15:07.130
2024-11-21T06:41:40.157
Modified
CVSSv3.1: 5.3 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | octopus | octopus_server | < 2021.3.13021 | Yes |
| Application | octopus | octopus_server | < 2022.1.2894 | Yes |
| Application | octopus | octopus_server | < 2022.2.6971 | Yes |
| Application | octopus | octopus_server | < 2022.3.2616 | Yes |