CVE-2019-8944

Severity CVSS v4.0:
Pending analysis
Type:
CWE-532 Information Exposure Through Log Files
Publication date:
20/02/2019
Last modified:
27/07/2022

Description

An Information Exposure issue in the Terraform deployment step in Octopus Deploy before 2019.1.8 (and before 2018.10.4 LTS) allows remote authenticated users to view sensitive Terraform output variables via log files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:octopus:octopus_deploy:*:*:*:*:*:*:*:* 2018.9.17 (including)
cpe:2.3:a:octopus:octopus_deploy:2018.10.0:*:*:*:lts:*:*:*
cpe:2.3:a:octopus:octopus_deploy:2018.10.1:*:*:*:lts:*:*:*
cpe:2.3:a:octopus:octopus_deploy:2018.10.2:*:*:*:lts:*:*:*
cpe:2.3:a:octopus:octopus_deploy:2018.10.3:*:*:*:lts:*:*:*
cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:* 2018.11.0 (including) 2019.1.8 (excluding)