CVE-2024-12226: Medium severity octopus kubernetes worker vulnerability
In affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes script pod log in clear-text. This was identified in Version 2 however it was determined that this could also be achieved in Version 1 and the fix was applied to both versions accordingly.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12226?
CVE-2024-12226 is classified as a medium severity vulnerability due to its potential exposure of sensitive information.
How do I fix CVE-2024-12226?
To fix CVE-2024-12226, update to the latest versions of the Octopus Kubernetes Worker and Agent where the vulnerability has been addressed.
Which versions are affected by CVE-2024-12226?
CVE-2024-12226 affects Octopus Kubernetes Worker and Agent from version 1 to version 2, inclusive.
What data is exposed by CVE-2024-12226?
CVE-2024-12226 allows sensitive variables to be logged in clear-text in the Kubernetes script pod log.
Is there a known workaround for CVE-2024-12226?
There are no known workarounds for CVE-2024-12226 other than applying the recommended updates.