Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-24566

Опубликовано: 09 сент. 2020
Источник: nvd
CVSS3: 7.5
CVSS2: 4.3
EPSS Низкий

Описание

In Octopus Deploy 2020.3.x before 2020.3.4 and 2020.4.x before 2020.4.1, if an authenticated user creates a deployment or runbook process using Azure steps and sets the step's execution location to run on the server/worker, then (under certain circumstances) the account password is exposed in cleartext in the verbose task logs output.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:octopus:octopus_deploy:*:*:*:*:*:*:*:*
Версия от 2020.3 (включая) до 2020.3.4 (исключая)

EPSS

Процентиль: 80%
0.01457
Низкий

7.5 High

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-532

Связанные уязвимости

github
больше 3 лет назад

In Octopus Deploy 2020.3.x before 2020.3.4 and 2020.4.x before 2020.4.1, if an authenticated user creates a deployment or runbook process using Azure steps and sets the step's execution location to run on the server/worker, then (under certain circumstances) the account password is exposed in cleartext in the verbose task logs output.

EPSS

Процентиль: 80%
0.01457
Низкий

7.5 High

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-532