First published: Wed Aug 18 2021(Updated: )
In Octopus Server after version 2018.8.2 if the Octopus Server Web Request Proxy is configured with authentication, the password is shown in plaintext in the UI.
Credit: security@octopus.com
Affected Software | Affected Version | How to fix |
---|---|---|
Octopus Deploy | >2018.8.2<2020.6.5310 | |
Octopus Deploy | >=2021.1.0<2021.1.7622 | |
Linux Kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-31820 is classified as a medium severity vulnerability due to the exposure of sensitive information.
To fix CVE-2021-31820, upgrade your Octopus Server to a version later than 2021.1.7622.
CVE-2021-31820 allows unauthorized users to view the proxy password in plaintext, potentially compromising system security.
CVE-2021-31820 affects Octopus Server versions between 2018.8.2 and 2021.1.7622.
Yes, if configured with authentication, the Octopus Server Web Request Proxy exposes the password in plaintext.