In affected versions of Octopus Server it is possible to reveal information about teams via the API due to an Insecure Direct Object Reference (IDOR) vulnerability
| Software | From | Fixed in |
|---|---|---|
| octopus / octopus_server | 2022.3.0 | 2022.3.10586.x |
| octopus / octopus_server | 2022.2.0 | 2022.2.7897.x |
| octopus / octopus_server | 2022.1.2121 | 2022.1.3135.x |