CVE-2021-31820

Severity CVSS v4.0:
Pending analysis
Type:
CWE-312 Cleartext Storage of Sensitive Information
Publication date:
18/08/2021
Last modified:
07/11/2023

Description

In Octopus Server after version 2018.8.2 if the Octopus Server Web Request Proxy is configured with authentication, the password is shown in plaintext in the UI.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:* 2018.8.2 (excluding) 2020.6.5310 (excluding)
cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:* 2021.1.0 (including) 2021.1.7622 (excluding)
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*