CVE-2024-12226 - CVE House
Back to Database
Status published Medium CVE-2024-12226

In affected versions of the Octopus Kubernetes worker or agent,...

Vulnerability Description

In affected versions of the Octopus Kubernetes worker or agent, sensitive variables could be written to the Kubernetes script pod log in clear-text. This was identified in Version 2 however it was determined that this could also be achieved in Version 1 and the fix was applied to both versions accordingly.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-12226

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Octopus Deploy

View all reports →

Affected Software

Kubernetes Worker or Kubernetes Agent
Vulnerable Versions:
1.x, 2.x

Timeline

Official Publish: January 16th, 2025
Last Modified: January 16th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)