First published: Tue Nov 01 2022(Updated: )
In affected versions of Octopus Server where access is managed by an external authentication provider, it was possible that the API key/keys of a disabled/deleted user were still valid after the access was revoked.
Credit: security@octopus.com
Affected Software | Affected Version | How to fix |
---|---|---|
Octopus Octopus Server | >=3.5<2022.1.3264 | |
Octopus Octopus Server | >=2022.2.6729<2022.2.8277 | |
Octopus Octopus Server | >=2022.3.348<2022.3.10586 | |
Octopus Octopus Server | >=2022.4.791<2022.4.2898 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.