CVE-2024-7998

LOW

Octopus Server - Info Disclosure

Title source: llm
STIX 2.1

Description

In affected versions of Octopus Server OIDC cookies were using the wrong expiration time which could result in them using the maximum lifespan.

Scores

CVSS v3 2.6
EPSS 0.0027
EPSS Percentile 50.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-613
Status published
Products (1)
octopus/octopus_server 2022.4.8332 - 2024.1.12931
Published Aug 21, 2024
Tracked Since Feb 18, 2026