It is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Octopus_server | Octopus | 2018.9.0 (including) | 2023.4.296 (excluding) |