CVE Vulnerabilities

CVE-2022-2721

Insertion of Sensitive Information into Log File

Published: Nov 25, 2022 | Modified: Apr 25, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In affected versions of Octopus Server it is possible for target discovery to print certain values marked as sensitive to log files in plaint-text in when verbose logging is enabled.

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
Octopus_serverOctopus2022.2.6729 (including)2022.2.7965 (excluding)
Octopus_serverOctopus2022.3.348 (including)2022.3.9163 (excluding)

Potential Mitigations

References