CVE-2022-1881
 
Severity Score
5.3
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
In affected versions of Octopus Server an Insecure Direct Object Reference vulnerability exists where it is possible for a user to download Project Exports from a Project they do not have permissions to access. This vulnerability only impacts projects within the same Space.
En las versiones afectadas de Octopus Server se presenta una vulnerabilidad de Referencia Directa de Objetos Insegura donde es posible que un usuario descargue Exportaciones de Proyectos desde un Proyecto al que no presenta permisos para acceder. Esta vulnerabilidad sólo afecta a proyectos dentro del mismo espacio
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-05-25 CVE Reserved
- 2022-07-15 CVE Published
- 2024-02-05 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-639: Authorization Bypass Through User-Controlled Key
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://advisories.octopus.com/post/2022/sa2022-06 | 2022-07-27 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Octopus Search vendor "Octopus" | Octopus Server Search vendor "Octopus" for product "Octopus Server" | >= 2021.1.6959 < 2021.3.13021 Search vendor "Octopus" for product "Octopus Server" and version " >= 2021.1.6959 < 2021.3.13021" | - |
Affected
| ||||||
Octopus Search vendor "Octopus" | Octopus Server Search vendor "Octopus" for product "Octopus Server" | >= 2022.1.2121 < 2022.1.2894 Search vendor "Octopus" for product "Octopus Server" and version " >= 2022.1.2121 < 2022.1.2894" | - |
Affected
| ||||||
Octopus Search vendor "Octopus" | Octopus Server Search vendor "Octopus" for product "Octopus Server" | >= 2022.2.6729 < 2022.2.6971 Search vendor "Octopus" for product "Octopus Server" and version " >= 2022.2.6729 < 2022.2.6971" | - |
Affected
| ||||||
Octopus Search vendor "Octopus" | Octopus Server Search vendor "Octopus" for product "Octopus Server" | >= 2022.3.348 < 2022.3.2616 Search vendor "Octopus" for product "Octopus Server" and version " >= 2022.3.348 < 2022.3.2616" | - |
Affected
|