First published: Thu Dec 14 2023(Updated: )
In affected versions of Octopus Server it is possible for the OpenID client secret to be logged in clear text during the configuration of Octopus Server.
Credit: security@octopus.com
Affected Software | Affected Version | How to fix |
---|---|---|
Octopus Deploy | >=2022.1.2121<2023.1.11942 | |
Octopus Deploy | >=2023.2.2028<2023.2.13151 | |
Octopus Deploy | >=2023.3.317<2023.3.5049 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1904 is a vulnerability in Octopus Server that allows the OpenID client secret to be logged in clear text during server configuration.
CVE-2023-1904 affects Octopus Server versions from 2022.1.2121 to 2023.1.11942, 2023.2.2028 to 2023.2.13151, and 2023.3.317 to 2023.3.5049.
CVE-2023-1904 is classified with a high severity due to the potential exposure of sensitive information.
To fix CVE-2023-1904, update Octopus Server to a version that is not affected by this vulnerability.
There is no documented workaround for CVE-2023-1904, hence updating is the recommended action.