CVE-2022-2782
9.1CRITICALIn affected versions of Octopus Server it is possible for a session token to be valid indefinitely due to improper validation of the session token parameters.
Published: 10/27/2022Updated: 5/7/2025
Description
In affected versions of Octopus Server it is possible for a session token to be valid indefinitely due to improper validation of the session token parameters.
AI AnalysisPowered by AI
Affected Products
octopusoctopus_server
octopusoctopus_server
octopusoctopus_server
References
- https://advisories.octopus.com/post/2022/sa2022-21/Vendor Advisory
- https://advisories.octopus.com/post/2022/sa2022-21/Vendor Advisory