CVE-2019-19375: Octopus Deploy
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
In Octopus Deploy before 2019.10.7, in a configuration where SSL offloading is enabled, the CSRF cookie was sometimes sent without the secure attribute. (The fix for this was backported to LTS versions 2019.6.14 and 2019.9.8.)
Affected products
- Octopus Octopus Deploy: before 2019.10.7 (fixed in 2019.10.7); from 2019.6.0, before 2019.6.14 (fixed in 2019.6.14); from 2019.9.0, before 2019.9.8 (fixed in 2019.9.8)
Published 2019-11-28. Last modified 2026-06-17.