PT-2020-14024 · Octopus Deploy · Octopus Deploy

Matt-Richardson

·

Published

2020-06-19

·

Updated

2021-07-21

·

CVE-2020-14470

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Octopus Deploy versions 2018.8.0 through 2019.x before 2019.12.2
Description The issue allows an authenticated user to trigger a deployment that leaks the Helm Chart repository password.
Recommendations For versions 2018.8.0 through 2019.x before 2019.12.2, update to version 2019.12.2 or later to resolve the issue.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-14470

Affected Products

Octopus Deploy