OpenID Client Secret Exposure in Octopus Server from Octopus Deploy
CVE-2023-1904
7.5HIGH
What is CVE-2023-1904?
A vulnerability exists in the Octopus Server where the OpenID client secret can be inadvertently logged in clear text during the server configuration process. This exposure of sensitive information could allow unauthorized users to access the OpenID client secret, potentially leading to security breaches. It is crucial for users to review their configurations and apply the necessary updates to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Octopus Server Windows 2022.2.7897
Octopus Server Windows < 2023.1.11942
Octopus Server Windows < 2023.2.13151
