In affected versions of Octopus Server it was identified that a session cookie could be used as the CSRF token
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://advisories.octopus.com/post/2022/sa2022-17/ | vendor advisory |