Vulnerabilities > Octopus > Octopus Deploy > 2019.6.2

DATE CVE VULNERABILITY TITLE RISK
2019-11-18 CVE-2019-19084 Unrestricted Upload of File with Dangerous Type vulnerability in Octopus Deploy
In Octopus Deploy 3.3.0 through 2019.10.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted package, triggering an exception that exposes underlying operating system details.
network
low complexity
octopus CWE-434
4.0
2019-08-05 CVE-2019-14525 Unspecified vulnerability in Octopus Deploy and Octopus Server
In Octopus Deploy 2019.4.0 through 2019.6.x before 2019.6.6, and 2019.7.x before 2019.7.6, an authenticated system administrator is able to view sensitive values by visiting a server configuration page or making an API call.
network
low complexity
octopus
4.0
2019-07-25 CVE-2019-14268 Information Exposure Through Log Files vulnerability in Octopus Deploy
In Octopus Deploy versions 3.0.19 to 2019.7.2, when a web request proxy is configured, an authenticated user (in certain limited circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext.
network
low complexity
octopus CWE-532
4.0