OpenID Client Secret Exposure in Octopus Server from Octopus Deploy
CVE-2023-1904

7.5HIGH

Key Information:

Vendor
CVE Published:
14 December 2023

What is CVE-2023-1904?

A vulnerability exists in the Octopus Server where the OpenID client secret can be inadvertently logged in clear text during the server configuration process. This exposure of sensitive information could allow unauthorized users to access the OpenID client secret, potentially leading to security breaches. It is crucial for users to review their configurations and apply the necessary updates to mitigate this risk.

Affected Version(s)

Octopus Server Windows 2022.2.7897

Octopus Server Windows < 2023.1.11942

Octopus Server Windows < 2023.2.13151

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.