CVE-2019-19084

MEDIUM

Octopus Deploy <2019.10.4 - Info Disclosure

Title source: llm
STIX 2.1

Description

In Octopus Deploy 3.3.0 through 2019.10.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted package, triggering an exception that exposes underlying operating system details.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://github.com/OctopusDeploy/Issues/issues/5971

Scores

CVSS v3 4.3
EPSS 0.0057
EPSS Percentile 68.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-434
Status published
Products (1)
octopus/octopus_deploy 3.3.0 - 2019.10.4
Published Nov 18, 2019
Tracked Since Feb 18, 2026