CVE-2022-1502

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/05/2022
Last modified:
08/08/2023

Description

Permissions were not properly verified in the API on projects using version control in Git. This allowed projects to be modified by users with only ProjectView permissions.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:octopus:server:*:*:*:*:*:*:*:* 2021.3 (including) 2021.3.12725 (excluding)
cpe:2.3:a:octopus:server:*:*:*:*:*:*:*:* 2022.1 (including) 2022.1.2454 (excluding)


References to Advisories, Solutions, and Tools