CVE-2019-8944

EUVD-2019-18331
An Information Exposure issue in the Terraform deployment step in Octopus Deploy before 2019.1.8 (and before 2018.10.4 LTS) allows remote authenticated users to view sensitive Terraform output variables via log files.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 47%
Affected Products (NVD)
VendorProductVersion
octopusoctopus_deploy
𝑥
≤ 2018.9.17
octopusoctopus_deploy
2018.10.0
octopusoctopus_deploy
2018.10.1
octopusoctopus_deploy
2018.10.2
octopusoctopus_deploy
2018.10.3
octopusoctopus_server
2018.11.0 ≤
𝑥
< 2019.1.8
𝑥
= Vulnerable software versions