First published: Tue Aug 27 2019(Updated: )
In Octopus Deploy 2019.7.3 through 2019.7.9, in certain circumstances, an authenticated user with VariableView permissions could view sensitive values. This is fixed in 2019.7.10.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Octopus Deploy | >=2019.7.3<=2019.7.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-15698 is considered medium due to the potential exposure of sensitive values.
To fix CVE-2019-15698, upgrade Octopus Deploy to version 2019.7.10 or later.
Authenticated users with VariableView permissions in Octopus Deploy versions 2019.7.3 to 2019.7.9 are affected by CVE-2019-15698.
CVE-2019-15698 addresses a vulnerability that allows unauthorized viewing of sensitive values by certain authenticated users.
CVE-2019-15698 was discovered as part of the vulnerability disclosure for Octopus Deploy versions 2019.7.3 through 2019.7.9.