Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cleartext storage of sensitive information in multiple versions of Octopus Server where in certain situations when running import or export processes, the password used to encrypt and decrypt sensitive values would be written to the logs in plaintext.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Octopus Server 安全漏洞
Vulnerability Description
Octopus Deploy是澳大利亚Octopus Deploy公司的一款用于.NET、Java等应用程序开发部署的自动化工具。 Octopus Server 存在安全漏洞,该漏洞源于将敏感信息明文存储在多个版本的Octopus Server中,在某些情况下,当运行导入或导出过程时,用于对敏感值进行加密和解密的密码会明文写入日志。
CVSS Information
N/A
Vulnerability Type
N/A