CVE Vulnerabilities

CVE-2024-12226

Insertion of Sensitive Information into Log File

Published: Jan 16, 2025 | Modified: Jan 16, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes script pod log in clear-text. This was identified in Version 2 however it was determined that this could also be achieved in Version 1 and the fix was applied to both versions accordingly.

Weakness

The product writes sensitive information to a log file.

Potential Mitigations

References