CVE-2019-19376 describes an application-level denial of service vulnerability in Octopus Deploy versions prior to 2019.10.6 (including backported fixes in LTS 2019.9.8 and 2019.6.14). An authenticated user with TeamEdit permissions can trigger this by sending a malformed Team API request that bypasses input validation. This vulnerability has a CVSS score of 6.5 (Medium), indicating it can be exploited remotely with low complexity by a low-privileged user, leading to high availability impact. There is no impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit or Nuclei, or entries in ExploitDB. The vulnerability has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2019.10.7CPE matchmatch criteria | cpe:2.3:a:octopus:octopus_deploy:*:*:*:*:-:*:*:* | ||
>= 2019.6.0, < 2019.6.14CPE matchmatch criteria | cpe:2.3:a:octopus:octopus_deploy:*:*:*:*:lts:*:*:* | ||
>= 2019.9.0, < 2019.9.8CPE matchmatch criteria | cpe:2.3:a:octopus:octopus_deploy:*:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.