VYPR
High severity7.5NVD Advisory· Published May 19, 2022· Updated Jun 17, 2026

CVE-2022-1670

CVE-2022-1670

Description

When generating a user invitation code in Octopus Server, the validity of this code can be set for a specific number of users. It was possible to bypass this restriction of validity to create extra user accounts above the initial number of invited users.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Octopus/Servercpe-rescue3 versions
    0.9+ 2 more
    • (no CPE)range: 0.9
    • cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:*range: >=0.9,<2021.3.12533
    • (no CPE)

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.