CVE-2021-31817: High severity octopus deploy vulnerability
When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the OctopusServer.txt log file in plaintext.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-31817?
CVE-2021-31817 is classified as a medium severity vulnerability due to the exposure of sensitive database credentials.
How do I fix CVE-2021-31817?
To fix CVE-2021-31817, ensure that you upgrade to the latest version of Octopus Server that addresses this vulnerability.
What type of data is exposed in CVE-2021-31817?
CVE-2021-31817 exposes the database password in plaintext within the OctopusServer.txt log file.
Which versions of Octopus Server are affected by CVE-2021-31817?
CVE-2021-31817 affects Octopus Server versions from 2020.6.0 to 2020.6.5146 and from 2021.1.0 to 2021.1.7316.
Is it safe to continue using vulnerable versions of Octopus Server affected by CVE-2021-31817?
It is not safe to continue using vulnerable versions affected by CVE-2021-31817 without applying the recommended updates or mitigations.