VYPR
Medium severity6.2NVD Advisory· Published Jan 22, 2021· Updated Jun 17, 2026

CVE-2021-21270

CVE-2021-21270

Description

OctopusDSC is a PowerShell module with DSC resources that can be used to install and configure an Octopus Deploy Server and Tentacle agent. In OctopusDSC version 4.0.977 and earlier a customer API key used to connect to Octopus Server is exposed via logging in plaintext. This vulnerability is patched in version 4.0.1002.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:octopus:octopusdsc:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:octopus:octopusdsc:*:*:*:*:*:*:*:*range: <4.0.1002
    • (no CPE)range: <=4.0.977
    • (no CPE)range: < 4.0.1002

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.