CVE-2023-1904

In affected versions of Octopus Server it is possible for the OpenID client secret to be logged in clear text during the configuration of Octopus Server.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.2 MEDIUM
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
OctopusCNA
4.2 MEDIUM
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 48%
VendorProductVersion
octopusoctopus_server
2022.1.2121 ≤
𝑥
< 2023.1.11942
octopusoctopus_server
2023.2.2028 ≤
𝑥
< 2023.2.13151
octopusoctopus_server
2023.3.317 ≤
𝑥
< 2023.3.5049
𝑥
= Vulnerable software versions