CVE Vulnerabilities

CVE-2019-14525

Published: Aug 05, 2019 | Modified: Nov 21, 2024
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In Octopus Deploy 2019.4.0 through 2019.6.x before 2019.6.6, and 2019.7.x before 2019.7.6, an authenticated system administrator is able to view sensitive values by visiting a server configuration page or making an API call.

Affected Software

NameVendorStart VersionEnd Version
Octopus_deployOctopus2019.4.0 (including)2019.6.6 (excluding)
Octopus_serverOctopus2019.7.0 (including)2019.7.6 (excluding)

References