In Octopus Deploy version 2018.5.1 to 2018.5.7, a user with Task View is able to view a password for a Service Fabric Cluster, when the Service Fabric Cluster target is configured in Azure Active Directory security mode and a deployment is executed with OctopusPrintVariables set to True. This is fixed in 2018.6.0.
2018-06-11T10:29:00.360
2024-11-21T03:44:34.397
Modified
CVSSv3.0: 7.5 (HIGH)
AV:N/AC:M/Au:S/C:P/I:N/A:N
6.8
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | octopus | octopus_server | ≤ 2018.5.7 | Yes |