CVE-2021-31820

HIGH

Octopus Server 2018.8.2-2020.6.5310 - Cleartext Storage of Sensitive Information in Web Request Proxy Configuration

Title source: llm
STIX 2.1

Description

In Octopus Server after version 2018.8.2 if the Octopus Server Web Request Proxy is configured with authentication, the password is shown in plaintext in the UI.

Scores

CVSS v3 7.5
EPSS 0.0061
EPSS Percentile 44.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-312
Status published
Products (1)
octopus/octopus_server 2018.8.2 - 2020.6.5310
Published Aug 18, 2021
Tracked Since Feb 18, 2026