First published: Wed Feb 20 2019(Updated: )
An Information Exposure issue in the Terraform deployment step in Octopus Deploy before 2019.1.8 (and before 2018.10.4 LTS) allows remote authenticated users to view sensitive Terraform output variables via log files.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Octopus Deploy | <=2018.9.17 | |
Octopus Deploy | =2018.10.0 | |
Octopus Deploy | =2018.10.1 | |
Octopus Deploy | =2018.10.2 | |
Octopus Deploy | =2018.10.3 | |
Octopus Deploy | >=2018.11.0<2019.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-8944 has a medium severity rating due to the potential exposure of sensitive information.
To fix CVE-2019-8944, upgrade Octopus Deploy to version 2019.1.8 or later, or 2018.10.4 LTS or later.
CVE-2019-8944 affects Octopus Deploy versions before 2019.1.8 and 2018.10.4 LTS.
Remote authenticated users of Octopus Deploy can be impacted by CVE-2019-8944 due to information exposure.
CVE-2019-8944 is classified as an Information Exposure vulnerability.