ZeroHour

CVE-2022-2781

CVSS 3.1
5.3 medium
EPSS
<1%p9
Published
()
Modified
Description

In affected versions of Octopus Server it was identified that the same encryption process was used for both encrypting session cookies and variables.

Vendors
octopus
Products
octopus server
Weakness
CWE-327
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.