CVE-2019-8944

An Information Exposure issue in the Terraform deployment step in Octopus Deploy before 2019.1.8 (and before 2018.10.4 LTS) allows remote authenticated users to view sensitive Terraform output variables via log files.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 58%
VendorProductVersion
octopusoctopus_deploy
𝑥
≤ 2018.9.17
octopusoctopus_deploy
2018.10.0
octopusoctopus_deploy
2018.10.1
octopusoctopus_deploy
2018.10.2
octopusoctopus_deploy
2018.10.3
octopusoctopus_server
2018.11.0 ≤
𝑥
< 2019.1.8
𝑥
= Vulnerable software versions