First published: Mon Nov 18 2019(Updated: )
A persistent cross-site scripting (XSS) vulnerability in Octopus Server 3.4.0 through 2019.10.5 allows remote authenticated attackers to inject arbitrary web script or HTML.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Octopus Deploy | >=3.4.0<=2019.10.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19085 is classified as a medium severity vulnerability due to the potential for remote authenticated attackers to exploit cross-site scripting (XSS).
To fix CVE-2019-19085, upgrade Octopus Server to the latest version beyond 2019.10.5 to address the XSS vulnerability.
CVE-2019-19085 affects users of Octopus Server versions ranging from 3.4.0 to 2019.10.5.
CVE-2019-19085 is a persistent cross-site scripting (XSS) vulnerability that allows arbitrary web script or HTML injection.
Yes, CVE-2019-19085 can be exploited remotely by authenticated attackers to inject malicious scripts.