CVE-2022-2781

Severity CVSS v4.0:
Pending analysis
Type:
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
Publication date:
06/10/2022
Last modified:
08/08/2023

Description

In affected versions of Octopus Server it was identified that the same encryption process was used for both encrypting session cookies and variables.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:* 3.2.10 (including) 2022.1.3154 (excluding)
cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:* 2022.2.6729 (including) 2022.2.7897 (excluding)
cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:* 2022.3.348 (including) 2022.3.10586 (excluding)


References to Advisories, Solutions, and Tools