Access Control Flaw in Octopus Server Affecting User Privileges
CVE-2022-2013
7.5HIGH
What is CVE-2022-2013?
In Octopus Server, private spaces enabled via the experimental feature flag could lead to a situation where all new users automatically gain access to the Script Console within their private spaces. This vulnerability allows unauthorized users to execute scripts and potentially manipulate server functions, posing a significant risk to the integrity of projects and data managed within the server.
Affected Version(s)
Octopus Server 2022.1.1495
Octopus Server < 2022.1.2647