6.5
CVE-2022-2828
- EPSS 0.27%
- Veröffentlicht 13.10.2022 05:15:08
- Zuletzt bearbeitet 15.05.2025 14:15:24
- Quelle security@octopus.com
- CVE-Watchlists
- Unerledigt
In affected versions of Octopus Server it is possible to reveal information about teams via the API due to an Insecure Direct Object Reference (IDOR) vulnerability
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Octopus ≫ Octopus Server Version >= 2022.1.2121 <= 2022.1.3135
Octopus ≫ Octopus Server Version >= 2022.2.0 <= 2022.2.7897
Octopus ≫ Octopus Server Version >= 2022.3.0 <= 2022.3.10586
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.27% | 0.497 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-639 Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.