CVE-2022-2782
In affected versions of Octopus Server it is possible for a session token to be valid indefinitely due to improper valid
In affected versions of Octopus Server it is possible for a session token to be valid indefinitely due to improper validation of the session token parameters.
CRITICAL · CVSS 9.1
EPSS 0.00261
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0