6.5

CVE-2019-8944

An Information Exposure issue in the Terraform deployment step in Octopus Deploy before 2019.1.8 (and before 2018.10.4 LTS) allows remote authenticated users to view sensitive Terraform output variables via log files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Octopus ≫ Octopus Deploy Version <= 2018.9.17
Octopus ≫ Octopus Deploy Version 2018.10.0 SwEdition lts
Octopus ≫ Octopus Deploy Version 2018.10.1 SwEdition lts
Octopus ≫ Octopus Deploy Version 2018.10.2 SwEdition lts
Octopus ≫ Octopus Deploy Version 2018.10.3 SwEdition lts
Octopus ≫ Octopus Server Version >= 2018.11.0 < 2019.1.8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.55% 0.718
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.

https://github.com/OctopusDeploy/Issues/issues/5314
Third Party Advisory
https://github.com/OctopusDeploy/Issues/issues/5315
Third Party Advisory