CVE-2023-1904: Octopus Server

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

In affected versions of Octopus Server it is possible for the OpenID client secret to be logged in clear text during the configuration of Octopus Server.

Affected products

  • Octopus Octopus Server: from 2022.1.2121, before 2023.1.11942 (fixed in 2023.1.11942); from 2023.2.2028, before 2023.2.13151 (fixed in 2023.2.13151); from 2023.3.317, before 2023.3.5049 (fixed in 2023.3.5049)

Published 2023-12-14. Last modified 2026-06-17.