CVE-2022-1901: Medium severity octopus deploy vulnerability
Published Aug 19, 2022
·Updated
In affected versions of Octopus Deploy it is possible to unmask sensitive variables by using variable preview.
Affected Software
8 affected components
Octopus Octopus Server>=2019.1.0<=2019.7.3
Octopus Octopus Server>=2020.1.0<=2020.6.5449
Octopus Octopus Server>=2021.1.6959<=2021.3.13021
Octopus Octopus Server>=2022.1.0<2022.1.3009
Octopus Octopus Server>=2022.2.6729<2022.2.7244
Octopus Octopus Server>=2022.3.348<2022.3.4953
Linux Linux kernel
Microsoft Windows
Remediation
Patch Available
Event History
Aug 19, 2022
CVE Published
via MITRE·07:55 AM
Data Sourced
via MITRE·07:55 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the CVE-2022-1901 vulnerability?
CVE-2022-1901 allows unmasking of sensitive variables in Octopus Deploy using variable preview functionality.
2
What versions of Octopus Deploy are affected by CVE-2022-1901?
CVE-2022-1901 affects Octopus Deploy versions between 2019.1.0 and 2022.2.7244.
3
What is the impact of CVE-2022-1901 on security?
The impact of CVE-2022-1901 is the potential exposure of sensitive information to unauthorized users.
4
How do I fix CVE-2022-1901?
To mitigate CVE-2022-1901, update to a version of Octopus Deploy that is not affected, specifically above 2022.2.7244.
5
Is there a workaround for CVE-2022-1901 if I cannot update?
There are no known workarounds for CVE-2022-1901, so updating is recommended for security.