First published: Tue May 02 2023(Updated: )
In affected versions of Octopus Deploy it is possible to unmask variable secrets using the variable preview function
Credit: security@octopus.com security@octopus.com
Affected Software | Affected Version | How to fix |
---|---|---|
Octopus Deploy | >=2018.3.0<2022.3.10929 | |
Octopus Deploy | >=2022.4.0<2022.4.8319 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2247 is classified as a medium severity vulnerability due to its potential to expose sensitive variable secrets.
To fix CVE-2023-2247, upgrade to a patched version of Octopus Deploy beyond versions 2022.3.10929 and 2022.4.8319.
CVE-2023-2247 affects Octopus Deploy versions from 2018.3.0 to 2022.3.10929 and 2022.4.0 to 2022.4.8319.
The impact of CVE-2023-2247 allows unauthorized users to view unmasked variable secrets, which can lead to data breaches.
There are no recommended workarounds for CVE-2023-2247; it is advised to upgrade to a secure version as soon as possible.