Back

MEDIUM

In affected versions of Octopus Server it is possible to reveal information about teams via the API due to an Insecure Direct Object Reference (IDOR) vulnerability

Published Oct 13, 2022

Description

In affected versions of Octopus Server it is possible to reveal information about teams via the API due to an Insecure Direct Object Reference (IDOR) vulnerability

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Octopus
Published Oct 13, 2022
Updated May 15, 2025
Reserved Aug 16, 2022
CISA Vulnrichment
Updated May 15, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Octopus
Published Oct 13, 2022
Updated May 15, 2025
Exploited since n/a
EUVD-2022-35064