CVE-2019-8944: Octopus Deploy
Medium severity, CVSS 6.5. EPSS: 1.5% chance of exploitation in the next 30 days.
An Information Exposure issue in the Terraform deployment step in Octopus Deploy before 2019.1.8 (and before 2018.10.4 LTS) allows remote authenticated users to view sensitive Terraform output variables via log files.
Affected products
- Octopus Octopus Deploy: up to and including 2018.9.17; version 2018.10.0 only; version 2018.10.1 only; version 2018.10.2 only; version 2018.10.3 only
- Octopus Octopus Server: from 2018.11.0, before 2019.1.8 (fixed in 2019.1.8)
Published 2019-02-20. Last modified 2026-06-17.