In affected versions of Octopus Server where access is...
Critical severity
Unreviewed
Published
Nov 1, 2022
to the GitHub Advisory Database
•
Updated May 6, 2025
Description
Published by the National Vulnerability Database
Nov 1, 2022
Published to the GitHub Advisory Database
Nov 1, 2022
Last updated
May 6, 2025
In affected versions of Octopus Server where access is managed by an external authentication provider, it was possible that the API key/keys of a disabled/deleted user were still valid after the access was revoked.
References