VulnerabilityAnalyzed
CVE-2023-4509
It is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt.
MEDIUM 4.3EPSS 0.23%
Does this matter?
Lower severity and a low EPSS score (0.23%). Track it; it rarely justifies an emergency change on its own.
Description
It is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.23% probability · 14th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-319
- Affected
- octopus/octopus server
- Source
- security@octopus.com
References
- https://advisories.octopus.com/post/2024/sa2024-02/Vendor Advisory
- https://advisories.octopus.com/post/2024/sa2024-02/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.