Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-2572

In affected versions of Octopus Server where access is managed by an external authentication provider, it was possible that the API key/keys of a disabled/deleted user were still valid after the access was revoked.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 42.1%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2022-2572


Contact Us

Shodan ® - All rights reserved