Vulnerabilities > Octopus > Octopus Server > 2018.5.1

DATE CVE VULNERABILITY TITLE RISK
2018-06-11 CVE-2018-12089 Information Exposure vulnerability in Octopus Server
In Octopus Deploy version 2018.5.1 to 2018.5.7, a user with Task View is able to view a password for a Service Fabric Cluster, when the Service Fabric Cluster target is configured in Azure Active Directory security mode and a deployment is executed with OctopusPrintVariables set to True.
network
high complexity
octopus CWE-200
7.5
2018-05-21 CVE-2018-11320 Information Exposure Through Log Files vulnerability in Octopus Server
In Octopus Deploy 2018.4.4 through 2018.5.1, Octopus variables that are sourced from the target do not have sensitive values obfuscated in the deployment logs.
network
low complexity
octopus CWE-532
critical
9.8