SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-14525

In Octopus Deploy 2019.4.0 through 2019.6.x before 2019.6.6, and 2019.7.x before 2019.7.6, an authenticated system administrator is able to view sensitive values by visiting a server configuration page or making an API call.

MEDIUM 4.9EPSS 1.53%

Does this matter?

Lower severity and a low EPSS score (1.53%). Track it; it rarely justifies an emergency change on its own.

Description

In Octopus Deploy 2019.4.0 through 2019.6.x before 2019.6.6, and 2019.7.x before 2019.7.6, an authenticated system administrator is able to view sensitive values by visiting a server configuration page or making an API call.

CVSS 3.0
4.9 MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
EPSS
1.53% probability · 73th percentile
CISA KEV
Not listed
Affected
octopus/octopus deploy · octopus/octopus server
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.