Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bash scripts can reveal sensitive variable values #6604

Closed
5 tasks done
adam-mccoy opened this issue Oct 5, 2020 · 1 comment
Closed
5 tasks done

Bash scripts can reveal sensitive variable values #6604

adam-mccoy opened this issue Oct 5, 2020 · 1 comment
Assignees
Labels
area/security kind/bug This issue represents a verified problem we are committed to solving priority (obsolete) This issue has been recognised as a priority and should be addressed as soon as possible
Milestone

Comments

@adam-mccoy
Copy link

Prerequisites

  • We are ready to publicly disclose this vulnerability or exploit according to our responsible disclosure process.
  • I have raised a CVE according to our CVE process
  • I have written a descriptive issue title
  • I have linked the original source of this report
  • I have tagged the issue appropriately (area/security, kind/bug, tag/regression?)

Description

Bash scripts, when configured in a certain way, can reveal reveal enough information to determine sensitive variable values in task logs. Other script types are not affected.

Affected versions

Octopus Server: 3.1.0 - 2020.4.0

Links

CVE: CVE-2020-25825
Internal Issue: https://github.com/OctopusDeploy/OctopusDeploy/issues/7304
PR: https://github.com/OctopusDeploy/OctopusDeploy/pull/7314

@adam-mccoy adam-mccoy added kind/bug This issue represents a verified problem we are committed to solving priority (obsolete) This issue has been recognised as a priority and should be addressed as soon as possible area/security labels Oct 5, 2020
@adam-mccoy adam-mccoy added this to the 2020.5.0 milestone Oct 5, 2020
@adam-mccoy adam-mccoy self-assigned this Oct 5, 2020
@adam-mccoy
Copy link
Author

Release Note: Fix bug where bash script can reveal sensitive variable values (CVE-2020-25825)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/security kind/bug This issue represents a verified problem we are committed to solving priority (obsolete) This issue has been recognised as a priority and should be addressed as soon as possible
Projects
None yet
Development

No branches or pull requests

1 participant