Total vulnerabilities in the database
When generating a user invitation code in Octopus Server, the validity of this code can be set for a specific number of users. It was possible to bypass this restriction of validity to create extra user accounts above the initial number of invited users.
Software | From | Fixed in |
---|---|---|
octopus / octopus_server | 0.9 | 2021.3.12533 |
octopus / octopus_server | 2022.1.0 | 2022.1.53 |