MEDIUM
In affected versions of Octopus Deploy it is possible to unmask sensitive variables by using variable preview
Published Aug 19, 2022
5.3
MEDIUMCVSS 3.1
EPSS 0.54%
Description
In affected versions of Octopus Deploy it is possible to unmask sensitive variables by using variable preview.
Affected products
-
- Version 2019.7.3StatusaffectedConstraints<unspecified
- Version 2022.2.6729StatusaffectedConstraints<unspecified
- Version 2022.3.348StatusaffectedConstraints<unspecified
- Version unspecifiedStatusaffectedConstraints<2022.1.3009
- Version unspecifiedStatusaffectedConstraints<2022.2.7244
- Version unspecifiedStatusaffectedConstraints<2022.3.4953
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Octopus Deploy | Octopus Server | n/a |
|
AND
OR
- ≥ 2019.1.0 · ≤ 2019.7.3
- ≥ 2020.1.0 · ≤ 2020.6.5449
- ≥ 2021.1.6959 · ≤ 2021.3.13021
- ≥ 2022.1.0 · < 2022.1.3009
- ≥ 2022.2.6729 · < 2022.2.7244
- ≥ 2022.3.348 · < 2022.3.4953
Running on/with
OR
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (1)
- https://advisories.octopus.com/post/2022/sa2022-09/ x_refsource_MISCMitigationPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://advisories.octopus.com/post/2022/sa2022-09/ | x_refsource_MISCMitigationPatchVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Octopus
Published Aug 19, 2022
Updated Aug 3, 2024
Reserved May 27, 2022
Link CVE-2022-1901
CISA Vulnrichment
Updated n/a