Description
In Octopus Deploy version 2018.5.1 to 2018.5.7, a user with Task View is able to view a password for a Service Fabric Cluster, when the Service Fabric Cluster target is configured in Azure Active Directory security mode and a deployment is executed with OctopusPrintVariables set to True. This is fixed in 2018.6.0.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-4069 | In Octopus Deploy version 2018.5.1 to 2018.5.7, a user with Task View is able to view a password for a Service Fabric Cluster, when the Service Fabric Cluster target is configured in Azure Active Directory security mode and a deployment is executed with OctopusPrintVariables set to True. This is fixed in 2018.6.0. |
References
| Link | Providers |
|---|---|
| https://github.com/OctopusDeploy/Issues/issues/4628 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T16:23:37.649Z
Reserved: 2018-06-11T00:00:00.000Z
Link: CVE-2018-12089
No data.
Status : Modified
Published: 2018-06-11T10:29:00.360
Modified: 2024-11-21T03:44:34.397
Link: CVE-2018-12089
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD