V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2023-1904
CVE
High

In affected versions of Octopus Server it is possible for the OpenID client secret to be logged in clear text during the configuration of O…

CVSS
7.5
High
EPSS
0.00
p30
Published
2023-01-01
Updated
2023-01-01
Description

In affected versions of Octopus Server it is possible for the OpenID client secret to be logged in clear text during the configuration of Octopus Server.

Tags · CWE
Pre-auth
CWE-532
CAPEC-215
Affected products
Octopus_server 2022.1.2121–2023.1.11942Octopus_server 2023.2.2028–2023.2.13151Octopus_server 2023.3.317–2023.3.5049
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Timeline
2023-01-01
Published
2023-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.004 · p30
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
octopus_server*Tracked
Source databases
CVE