Incorrect Expiration Time in OIDC Cookies Could Lead to Lifespan Exceedance
CVE-2024-7998

2.6LOW

Key Information:

Vendor
CVE Published:
21 August 2024

What is CVE-2024-7998?

An issue has been identified in Octopus Server relating to OIDC cookies where the expiration time was incorrectly set. This misconfiguration allows OIDC cookies to utilize the maximum lifespan permitted, which could potentially enable unauthorized access or prolong session persistence beyond intended limits. Admins are advised to update to the latest version to mitigate this issue.

Affected Version(s)

Octopus Server Windows 2022.4.8332 < 2024.1.12931

Octopus Server Windows 2024.1.437 < 2024.1.12931

Octopus Server Windows 2024.2.101 < 2024.2.9313

References

CVSS V3.1

Score:
2.6
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.