CVE-2021-31820
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
In Octopus Server after version 2018.8.2 if the Octopus Server Web Request Proxy is configured with authentication, the password is shown in plaintext in the UI.
Affected (2)
Products: Octopus: Octopus Server
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| After 2018.8.2 to 2020.6.5310 |
| Running on/with | Platform Versions |
|---|---|
Linux Linux Kernel | All versions |
Microsoft Windows | All versions |
References (2)
Source: security@octopus.com
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.