Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In affected versions of Octopus Server it was possible for a low privileged user to manipulate an API request to change the signing key expiration and revocation time frames via an API endpoint that had incorrect permission validation. It was not possible to expose the signing keys using this vulnerability.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Octopus Server 安全漏洞
Vulnerability Description
Octopus Server是澳大利亚Octopus公司的一个用于持续交付的部署自动化和发布管理工具。 Octopus Server存在安全漏洞,该漏洞源于API端点权限验证不正确,可能导致低权限用户通过操纵API请求更改签名密钥过期和吊销时间范围。
CVSS Information
N/A
Vulnerability Type
N/A