In affected versions of Octopus Server it is possible to reveal information about teams via the API due to an Insecure Direct Object Reference (IDOR) vulnerability
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-35064 | In affected versions of Octopus Server it is possible to reveal information about teams via the API due to an Insecure Direct Object Reference (IDOR) vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://advisories.octopus.com/post/2022/sa2022-19/ |
|
History
Thu, 15 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Octopus
Published:
Updated: 2025-05-15T13:57:47.007Z
Reserved: 2022-08-16T00:00:00.000Z
Link: CVE-2022-2828
Updated: 2024-08-03T00:52:59.569Z
Status : Modified
Published: 2022-10-13T05:15:08.947
Modified: 2025-05-15T14:15:24.653
Link: CVE-2022-2828
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD