Beveiligingsadvies

CVE-2022-2572

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-11-01 00:00:00
Laatst bijgewerkt 2025-05-06 03:37:49
Toegewezen door Octopus
CVSS-score 9.8
Status PUBLISHED

Beschrijving

In affected versions of Octopus Server where access is managed by an external authentication provider, it was possible that the API key/keys of a disabled/deleted user were still valid after the access was revoked.