CVE-2019-15698: Octopus Server

Medium severity, CVSS 4.3. EPSS: 0.9% chance of exploitation in the next 30 days.

In Octopus Deploy 2019.7.3 through 2019.7.9, in certain circumstances, an authenticated user with VariableView permissions could view sensitive values. This is fixed in 2019.7.10.

Affected products

  • Octopus Octopus Server: from 2019.7.3, up to and including 2019.7.9

Published 2019-08-27. Last modified 2026-06-17.