6.5

CVE-2019-8944

An Information Exposure issue in the Terraform deployment step in Octopus Deploy before 2019.1.8 (and before 2018.10.4 LTS) allows remote authenticated users to view sensitive Terraform output variables via log files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OctopusOctopus Deploy Version <= 2018.9.17
OctopusOctopus Deploy Version2018.10.0 SwEditionlts
OctopusOctopus Deploy Version2018.10.1 SwEditionlts
OctopusOctopus Deploy Version2018.10.2 SwEditionlts
OctopusOctopus Deploy Version2018.10.3 SwEditionlts
OctopusOctopus Server Version >= 2018.11.0 < 2019.1.8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.55% 0.718
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.

https://github.com/OctopusDeploy/Issues/issues/5314
Third Party Advisory
https://github.com/OctopusDeploy/Issues/issues/5315
Third Party Advisory