PT-2021-14377 · Octopus Deploy · Octopusdsc

Wizedkyle

·

Published

2021-01-22

·

Updated

2021-02-01

·

CVE-2021-21270

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: OctopusDSC versions 4.0.977 and earlier
Description: The issue concerns the exposure of a customer API key used to connect to Octopus Server via logging in plaintext. This occurs in the context of OctopusDSC, a PowerShell module with DSC resources for installing and configuring an Octopus Deploy Server and Tentacle agent.
Recommendations: For OctopusDSC versions 4.0.977 and earlier, update to version 4.0.1002 or later to resolve the issue.

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-21270
GHSA-PHMM-RFG9-94FM

Affected Products

Octopusdsc