CVE-2019-15698: Medium severity octopus deploy vulnerability
Published Aug 27, 2019
·Updated
In Octopus Deploy 2019.7.3 through 2019.7.9, in certain circumstances, an authenticated user with VariableView permissions could view sensitive values. This is fixed in 2019.7.10.
Affected Software
1 affected component
Octopus Octopus Server>=2019.7.3<=2019.7.9
Event History
Aug 27, 2019
CVE Published
via MITRE·04:53 PM
Data Sourced
via MITRE·04:53 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-15698?
The severity of CVE-2019-15698 is considered medium due to the potential exposure of sensitive values.
2
How do I fix CVE-2019-15698?
To fix CVE-2019-15698, upgrade Octopus Deploy to version 2019.7.10 or later.
3
Who is affected by CVE-2019-15698?
Authenticated users with VariableView permissions in Octopus Deploy versions 2019.7.3 to 2019.7.9 are affected by CVE-2019-15698.
4
What vulnerability does CVE-2019-15698 address?
CVE-2019-15698 addresses a vulnerability that allows unauthorized viewing of sensitive values by certain authenticated users.
5
When was CVE-2019-15698 discovered?
CVE-2019-15698 was discovered as part of the vulnerability disclosure for Octopus Deploy versions 2019.7.3 through 2019.7.9.