In affected versions of Octopus Server it is possible for a session token to be valid indefinitely due to improper validation of the session token parameters.
According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”
Name | Vendor | Start Version | End Version |
---|---|---|---|
Octopus_server | Octopus | * | 2022.2.8351 (excluding) |
Octopus_server | Octopus | 2022.3.0 (including) | 2022.3.10586 (excluding) |
Octopus_server | Octopus | 2022.4.0 (including) | 2022.4.2898 (excluding) |