ZeroHour

CVE-2019-8944

CVSS 3.0
6.5 medium
EPSS
2%p74
Published
()
Modified
Description

An Information Exposure issue in the Terraform deployment step in Octopus Deploy before 2019.1.8 (and before 2018.10.4 LTS) allows remote authenticated users to view sensitive Terraform output variables via log files.

Vendors
octopus
Products
octopus deploy, octopus server
Weakness
CWE-532
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.