CVE Published: 01/11/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: Octopus |
Vendor: Octopus Deploy |
Product: Octopus Server Status : PUBLISHED
CVE-2022-2572 Description
In affected versions of Octopus Server where access is managed by an external authentication provider, it was possible that the API key/keys of a disabled/deleted user were still valid after the access was revoked.