Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-6972


In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the task log in clear-text.


Published

2024-07-25T06:15:01.967

Last Modified

2025-07-02T17:26:41.540

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-319

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application octopus octopus_server < 2024.1.12759 Yes
Application octopus octopus_server < 2024.2.9193 Yes
Operating System linux linux_kernel - No
Operating System microsoft windows - No

References