Incorrect Expiration Time in OIDC Cookies Could Lead to Lifespan Exceedance
CVE-2024-7998
2.6LOW
What is CVE-2024-7998?
An issue has been identified in Octopus Server relating to OIDC cookies where the expiration time was incorrectly set. This misconfiguration allows OIDC cookies to utilize the maximum lifespan permitted, which could potentially enable unauthorized access or prolong session persistence beyond intended limits. Admins are advised to update to the latest version to mitigate this issue.
Affected Version(s)
Octopus Server Windows 2022.4.8332 < 2024.1.12931
Octopus Server Windows 2024.1.437 < 2024.1.12931
Octopus Server Windows 2024.2.101 < 2024.2.9313