CVE-2019-14525: Octopus Deploy

Medium severity, CVSS 4.9. EPSS: 1.5% chance of exploitation in the next 30 days.

In Octopus Deploy 2019.4.0 through 2019.6.x before 2019.6.6, and 2019.7.x before 2019.7.6, an authenticated system administrator is able to view sensitive values by visiting a server configuration page or making an API call.

Affected products

  • Octopus Octopus Deploy: from 2019.4.0, before 2019.6.6 (fixed in 2019.6.6)
  • Octopus Octopus Server: from 2019.7.0, before 2019.7.6 (fixed in 2019.7.6)

Published 2019-08-05. Last modified 2026-06-17.