CVE-2019-8944: Medium severity octopus deploy vulnerability
Published Feb 20, 2019
·Updated
An Information Exposure issue in the Terraform deployment step in Octopus Deploy before 2019.1.8 (and before 2018.10.4 LTS) allows remote authenticated users to view sensitive Terraform output variables via log files.
Affected Software
6 affected components
Octopus Octopus Deploy<=2018.9.17
Octopus Octopus Deploy=2018.10.0
Octopus Octopus Deploy=2018.10.1
Octopus Octopus Deploy=2018.10.2
Octopus Octopus Deploy=2018.10.3
Octopus Octopus Server>=2018.11.0<2019.1.8
Event History
Feb 20, 2019
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Data Sourced
via NVD·03:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-8944?
CVE-2019-8944 has a medium severity rating due to the potential exposure of sensitive information.
2
How do I fix CVE-2019-8944?
To fix CVE-2019-8944, upgrade Octopus Deploy to version 2019.1.8 or later, or 2018.10.4 LTS or later.
3
Which versions of Octopus Deploy are affected by CVE-2019-8944?
CVE-2019-8944 affects Octopus Deploy versions before 2019.1.8 and 2018.10.4 LTS.
4
Who is impacted by CVE-2019-8944?
Remote authenticated users of Octopus Deploy can be impacted by CVE-2019-8944 due to information exposure.
5
What type of issue is CVE-2019-8944 classified as?
CVE-2019-8944 is classified as an Information Exposure vulnerability.