CVE-2019-19376
28.11.2019, 17:15
In Octopus Deploy before 2019.10.6, an authenticated user with TeamEdit permission could send a malformed Team API request that bypasses input validation and causes an application level denial of service condition. (The fix for this was also backported to LTS 2019.9.8 and LTS 2019.6.14.)Enginsight
| Vendor | Product | Version |
|---|---|---|
| octopus | octopus_deploy | 𝑥 < 2019.10.7 |
| octopus | octopus_deploy | 2019.6.0 ≤ 𝑥 < 2019.6.14 |
| octopus | octopus_deploy | 2019.9.0 ≤ 𝑥 < 2019.9.8 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration