Vulnerability CVE-2022-1670


Published: 2022-05-19

Description:
When generating a user invitation code in Octopus Server, the validity of this code can be set for a specific number of users. It was possible to bypass this restriction of validity to create extra user accounts above the initial number of invited users.

 References:
https://advisories.octopus.com/post/2022/sa2022-04/

Copyright 2026, cxsecurity.com

 

Back to Top