CVE-2021-31820: High severity octopus deploy vulnerability
Published Aug 18, 2021
·Updated
In Octopus Server after version 2018.8.2 if the Octopus Server Web Request Proxy is configured with authentication, the password is shown in plaintext in the UI.
Affected Software
4 affected components
Octopus Octopus Server>2018.8.2<2020.6.5310
Octopus Octopus Server>=2021.1.0<2021.1.7622
Linux Linux kernel
Microsoft Windows
Event History
Aug 18, 2021
CVE Published
via MITRE·10:43 AM
Data Sourced
via MITRE·10:43 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-31820?
CVE-2021-31820 is classified as a medium severity vulnerability due to the exposure of sensitive information.
2
How do I fix CVE-2021-31820?
To fix CVE-2021-31820, upgrade your Octopus Server to a version later than 2021.1.7622.
3
What impact does CVE-2021-31820 have on users?
CVE-2021-31820 allows unauthorized users to view the proxy password in plaintext, potentially compromising system security.
4
Which versions of Octopus Server are affected by CVE-2021-31820?
CVE-2021-31820 affects Octopus Server versions between 2018.8.2 and 2021.1.7622.
5
Is the Octopus Server Web Request Proxy vulnerable due to CVE-2021-31820?
Yes, if configured with authentication, the Octopus Server Web Request Proxy exposes the password in plaintext.