In affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes script pod log in clear-text. This was identified in Version 2 however it was determined that this could also be achieved in Version 1 and the fix was applied to both versions accordingly.
History

Thu, 16 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 07:00:00 +0000

Type Values Removed Values Added
Description In affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes script pod log in clear-text. This was identified in Version 2 however it was determined that this could also be achieved in Version 1 and the fix was applied to both versions accordingly.
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Octopus

Published: 2025-01-16T06:48:20.279Z

Updated: 2025-01-16T14:21:30.387Z

Reserved: 2024-12-05T03:36:29.513Z

Link: CVE-2024-12226

cve-icon Vulnrichment

Updated: 2025-01-16T14:21:24.664Z

cve-icon NVD

Status : Received

Published: 2025-01-16T07:15:26.333

Modified: 2025-01-16T07:15:26.333

Link: CVE-2024-12226

cve-icon Redhat

No data.