Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In Octopus Deploy versions 3.0.19 to 2019.7.2, when a web request proxy is configured, an authenticated user (in certain limited circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is fixed in 2019.7.3. The fix was back-ported to LTS 2019.6.5 as well as LTS 2019.3.7.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Octopus Deploy 日志信息泄露漏洞
Vulnerability Description
Octopus Deploy是澳大利亚Octopus Deploy公司的一款用于.NET、Java等应用程序开发部署的自动化工具。 Octopus Deploy 3.0.19版本至2019.7.2版本中存在安全漏洞,该漏洞源于程序将Web请求代理密码以明文的形式写入到部署日志中。攻击者可利用该漏洞获取信息。
CVSS Information
N/A
Vulnerability Type
N/A