In Octopus Deploy 2018.4.4 through 2018.5.1, Octopus variables that are sourced from the target do not have sensitive values obfuscated in the deployment logs.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://github.com/OctopusDeploy/Issues/issues/4578 | issue tracking third party advisory |