VYPR
High severity7.5NVD Advisory· Published Jul 8, 2021· Updated Jun 17, 2026

CVE-2021-31817

CVE-2021-31817

Description

When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the OctopusServer.txt log file in plaintext.

Affected products

3
  • Octopus/Servercpe-rescue3 versions
    2020.6.4671+ 2 more
    • (no CPE)range: 2020.6.4671
    • cpe:2.3:a:octopus:server:*:*:*:*:*:*:*:*range: >=2020.6.0,<2020.6.5146
    • (no CPE)

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.