CVE-2022-1670

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/05/2022
Last modified:
27/07/2022

Description

When generating a user invitation code in Octopus Server, the validity of this code can be set for a specific number of users. It was possible to bypass this restriction of validity to create extra user accounts above the initial number of invited users.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:* 0.9 (including) 2021.3.12533 (excluding)
cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:* 2022.1.0 (including) 2022.1.53 (excluding)


References to Advisories, Solutions, and Tools