Plaintext Password Exposure in Octopus Server by Octopus Deploy
CVE-2021-31820
7.5HIGH
What is CVE-2021-31820?
A vulnerability exists in Octopus Server versions post-2018.8.2, where configuring the Web Request Proxy with authentication leads to the exposure of passwords in plaintext within the user interface. This flaw may allow unauthorized access to sensitive credentials, highlighting a significant security concern for users relying on this feature.
Affected Version(s)
Octopus Server 2018.8.2
Octopus Server < 2020.6.5310
Octopus Server 2021.1.7149