CVE-2021-31821: Medium severity octopus tentacle vulnerability
Published Jan 19, 2022
·Updated
When the Windows Tentacle docker image starts up it logs all the commands that it runs along with the arguments, which writes the Octopus Server API key in plaintext. This does not affect the Linux Docker image
Affected Software
2 affected components
Octopus Tentacle<6.1.1266
Microsoft Windows
Event History
Jan 19, 2022
CVE Published
via MITRE·05:25 AM
Data Sourced
via MITRE·05:25 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-31821?
CVE-2021-31821 is classified as a medium severity vulnerability due to the exposure of sensitive information.
2
How do I fix CVE-2021-31821?
To fix CVE-2021-31821, upgrade the Octopus Tentacle to version 6.1.1266 or later.
3
What does CVE-2021-31821 affect?
CVE-2021-31821 affects the Windows version of the Octopus Tentacle docker image.
4
Why is CVE-2021-31821 a concern?
CVE-2021-31821 is concerning because it logs the Octopus Server API key in plaintext, exposing it to potential compromise.
5
Is the Linux Docker image affected by CVE-2021-31821?
No, the Linux Docker image is not affected by CVE-2021-31821.