PT-2019-14233 · Octopus · Octopus Tentacle
Flin-8
·
Publicado
2019-08-23
·
Atualizado
2022-07-27
·
CVE-2019-15508
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Octopus Tentacle versions 3.0.8 through 5.0.0
Description
The issue allows an authenticated user, under specific circumstances involving OctopusPrintVariables, to trigger a deployment that writes the web request proxy password to the deployment log in cleartext when a web request proxy is configured.
Recommendations
For versions 3.0.8 through 4.0.6, update to version 4.0.7.
For versions 4.0.7 through 5.0.0, update to version 5.0.1.
Correção
Cleartext Storage of Sensitive Information
Insertion into Log File
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Octopus Tentacle