CVE-2019-19084
18.11.2019, 16:15
In Octopus Deploy 3.3.0 through 2019.10.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted package, triggering an exception that exposes underlying operating system details.Enginsight
Vendor | Product | Version |
---|---|---|
octopus | octopus_deploy | 3.3.0 ≤ 𝑥 ≤ 2019.10.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration