CVE-2023-4509: Medium severity Octopus Octopus Server vulnerability
Published Apr 17, 2024
·Updated
It is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt.
Affected Software
3 affected components
All of the following
Octopus Octopus Server>=2018.9.0<2023.4.296
Any of the following
Linux Linux kernel
Microsoft Windows
Event History
Apr 17, 2024
CVE Published
via MITRE·11:10 PM
Data Sourced
via MITRE·11:10 PM
DescriptionSeverityWeakness
Apr 18, 2024
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-4509?
CVE-2023-4509 is classified as a medium-severity vulnerability due to sensitive information exposure.
2
How do I fix CVE-2023-4509?
To fix CVE-2023-4509, ensure that audit log configurations do not log API keys in clear text.
3
What software versions are affected by CVE-2023-4509?
CVE-2023-4509 affects Octopus Server versions from 2018.9.0 to 2023.4.296.
4
What type of data is exposed in CVE-2023-4509?
CVE-2023-4509 exposes API keys in clear text in the audit log file after invalid login attempts.
5
Is there a workaround for CVE-2023-4509?
A potential workaround for CVE-2023-4509 is to limit access to audit logs to trusted personnel only.