Octopus · Octopus Deploy · CVE-2018-12089
**Name of the Vulnerable Software and Affected Versions**
Octopus Deploy versions 2018.5.1 through 2018.5.7
**Description**
A security issue allows a user with Task View permissions to view a password for a Service Fabric Cluster when the cluster target is configured in Azure Active Directory security mode and a deployment is executed with `OctopusPrintVariables` set to True.
**Recommendations**
For Octopus Deploy versions 2018.5.1 through 2018.5.7, update to version 2018.6.0 to resolve the issue.