CVE-2019-19375
28.11.2019, 17:15
In Octopus Deploy before 2019.10.7, in a configuration where SSL offloading is enabled, the CSRF cookie was sometimes sent without the secure attribute. (The fix for this was backported to LTS versions 2019.6.14 and 2019.9.8.)
Vendor | Product | Version |
---|---|---|
octopus | octopus_deploy | 𝑥 < 2019.10.7 |
octopus | octopus_deploy | 2019.6.0 ≤ 𝑥 < 2019.6.14 |
octopus | octopus_deploy | 2019.9.0 ≤ 𝑥 < 2019.9.8 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration