VulnerabilityModified
CVE-2019-14525
In Octopus Deploy 2019.4.0 through 2019.6.x before 2019.6.6, and 2019.7.x before 2019.7.6, an authenticated system administrator is able to view sensitive values by visiting a server configuration page or making an API call.
MEDIUM 4.9EPSS 1.53%
Does this matter?
Lower severity and a low EPSS score (1.53%). Track it; it rarely justifies an emergency change on its own.
Description
In Octopus Deploy 2019.4.0 through 2019.6.x before 2019.6.6, and 2019.7.x before 2019.7.6, an authenticated system administrator is able to view sensitive values by visiting a server configuration page or making an API call.
- CVSS 3.0
- 4.9 MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.53% probability · 73th percentile
- CISA KEV
- Not listed
- Affected
- octopus/octopus deploy · octopus/octopus server
- Source
- cve@mitre.org
References
- https://github.com/OctopusDeploy/Issues/issues/5753Third Party Advisory
- https://github.com/OctopusDeploy/Issues/issues/5754Third Party Advisory
- https://octopus.com/downloads/compare?from=2019.6.6&to=2019.7.7Vendor Advisory
- https://github.com/OctopusDeploy/Issues/issues/5753Third Party Advisory
- https://github.com/OctopusDeploy/Issues/issues/5754Third Party Advisory
- https://octopus.com/downloads/compare?from=2019.6.6&to=2019.7.7Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.