CVE-2020-14470: Medium severity octopus deploy vulnerability
Published Jun 19, 2020
·Updated
In Octopus Deploy 2018.8.0 through 2019.x before 2019.12.2, an authenticated user with could trigger a deployment that leaks the Helm Chart repository password.
Affected Software
1 affected component
Octopus Octopus Deploy>=2018.8.0<2019.12.2
Event History
Jun 19, 2020
CVE Published
via MITRE·02:48 PM
Data Sourced
via MITRE·02:48 PM
Description
Frequently Asked Questions
1
What is CVE-2020-14470?
CVE-2020-14470 is a vulnerability in Octopus Deploy 2018.8.0 through 2019.x before 2019.12.2 that allows an authenticated user to trigger a deployment leaking the Helm Chart repository password.
2
How severe is CVE-2020-14470?
CVE-2020-14470 has a severity level of 6.5 (medium).
3
How can I fix CVE-2020-14470?
To fix CVE-2020-14470, ensure you have upgraded Octopus Deploy to version 2019.12.2 or later.