Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g7j7-888j-qv8x

Опубликовано: 01 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

In affected versions of Octopus Server where access is managed by an external authentication provider, it was possible that the API key/keys of a disabled/deleted user were still valid after the access was revoked.

In affected versions of Octopus Server where access is managed by an external authentication provider, it was possible that the API key/keys of a disabled/deleted user were still valid after the access was revoked.

EPSS

Процентиль: 60%
0.00392
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.8
nvd
больше 3 лет назад

In affected versions of Octopus Server where access is managed by an external authentication provider, it was possible that the API key/keys of a disabled/deleted user were still valid after the access was revoked.

EPSS

Процентиль: 60%
0.00392
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287