CVE Vulnerabilities

CVE-2024-6972

Cleartext Transmission of Sensitive Information

Published: Jul 25, 2024 | Modified: Jul 02, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the task log in clear-text.

Weakness

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Octopus_server Octopus 2024.1.437 (including) 2024.1.12759 (excluding)
Octopus_server Octopus 2024.2.101 (including) 2024.2.9193 (excluding)

Potential Mitigations

References