In affected versions of Octopus Server it was identified that a session cookie could be used as the CSRF token