Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-1881


In affected versions of Octopus Server an Insecure Direct Object Reference vulnerability exists where it is possible for a user to download Project Exports from a Project they do not have permissions to access. This vulnerability only impacts projects within the same Space.


Published

2022-07-15T08:15:07.130

Last Modified

2024-11-21T06:41:40.157

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-639

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application octopus octopus_server < 2021.3.13021 Yes
Application octopus octopus_server < 2022.1.2894 Yes
Application octopus octopus_server < 2022.2.6971 Yes
Application octopus octopus_server < 2022.3.2616 Yes

References