Sensitive Information Exposure in Octopus Server Logging
CVE-2022-2721
7.5HIGH
What is CVE-2022-2721?
In certain versions of Octopus Server, when verbose logging is enabled, sensitive information can be inadvertently logged in plaintext. This situation can lead to unauthorized access to sensitive data by individuals who can view the log files, potentially exposing confidential information without proper safeguards.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Octopus Server 2022.2.6729
Octopus Server < 2022.2.7965
Octopus Server 2022.3.348
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
