Sensitive Information Exposure in Octopus Server Logging
CVE-2022-2721
7.5HIGH
What is CVE-2022-2721?
In certain versions of Octopus Server, when verbose logging is enabled, sensitive information can be inadvertently logged in plaintext. This situation can lead to unauthorized access to sensitive data by individuals who can view the log files, potentially exposing confidential information without proper safeguards.
Affected Version(s)
Octopus Server 2022.2.6729
Octopus Server < 2022.2.7965
Octopus Server 2022.3.348