In affected versions of Octopus Server it is possible for the OpenID client secret to be logged in clear text during the configuration of Octopus Server.
The product writes sensitive information to a log file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Octopus_server | Octopus | 2022.1.2121 (including) | 2023.1.11942 (excluding) |
Octopus_server | Octopus | 2023.2.2028 (including) | 2023.2.13151 (excluding) |
Octopus_server | Octopus | 2023.3.317 (including) | 2023.3.5049 (excluding) |