6.5

CVE-2019-8944

An Information Exposure issue in the Terraform deployment step in Octopus Deploy before 2019.1.8 (and before 2018.10.4 LTS) allows remote authenticated users to view sensitive Terraform output variables via log files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OctopusOctopus Deploy Version <= 2018.9.17
OctopusOctopus Deploy Version2018.10.0 SwEditionlts
OctopusOctopus Deploy Version2018.10.1 SwEditionlts
OctopusOctopus Deploy Version2018.10.2 SwEditionlts
OctopusOctopus Deploy Version2018.10.3 SwEditionlts
OctopusOctopus Server Version >= 2018.11.0 < 2019.1.8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.472
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.