CVE-2019-8944
 
Severity Score
6.5
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
An Information Exposure issue in the Terraform deployment step in Octopus Deploy before 2019.1.8 (and before 2018.10.4 LTS) allows remote authenticated users to view sensitive Terraform output variables via log files.
Un fallo de exposición de información en el paso de despliegue de Terraform en Octopus Deploy, en versiones anteriores a la 2019.1.8 (anteriores a la 2018.10.4 LTS) permite a los usuarios autenticados remotos visualizar variables de salida sensibles de Terraform mediante archivos de log.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2019-02-19 CVE Reserved
- 2019-02-20 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-532: Insertion of Sensitive Information into Log File
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/OctopusDeploy/Issues/issues/5314 | Third Party Advisory | |
https://github.com/OctopusDeploy/Issues/issues/5315 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Octopus Search vendor "Octopus" | Octopus Deploy Search vendor "Octopus" for product "Octopus Deploy" | <= 2018.9.17 Search vendor "Octopus" for product "Octopus Deploy" and version " <= 2018.9.17" | - |
Affected
| ||||||
Octopus Search vendor "Octopus" | Octopus Deploy Search vendor "Octopus" for product "Octopus Deploy" | 2018.10.0 Search vendor "Octopus" for product "Octopus Deploy" and version "2018.10.0" | lts |
Affected
| ||||||
Octopus Search vendor "Octopus" | Octopus Deploy Search vendor "Octopus" for product "Octopus Deploy" | 2018.10.1 Search vendor "Octopus" for product "Octopus Deploy" and version "2018.10.1" | lts |
Affected
| ||||||
Octopus Search vendor "Octopus" | Octopus Deploy Search vendor "Octopus" for product "Octopus Deploy" | 2018.10.2 Search vendor "Octopus" for product "Octopus Deploy" and version "2018.10.2" | lts |
Affected
| ||||||
Octopus Search vendor "Octopus" | Octopus Deploy Search vendor "Octopus" for product "Octopus Deploy" | 2018.10.3 Search vendor "Octopus" for product "Octopus Deploy" and version "2018.10.3" | lts |
Affected
| ||||||
Octopus Search vendor "Octopus" | Octopus Server Search vendor "Octopus" for product "Octopus Server" | >= 2018.11.0 < 2019.1.8 Search vendor "Octopus" for product "Octopus Server" and version " >= 2018.11.0 < 2019.1.8" | - |
Affected
|