CVE-2019-19375: Octopus Deploy

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

In Octopus Deploy before 2019.10.7, in a configuration where SSL offloading is enabled, the CSRF cookie was sometimes sent without the secure attribute. (The fix for this was backported to LTS versions 2019.6.14 and 2019.9.8.)

Affected products

  • Octopus Octopus Deploy: before 2019.10.7 (fixed in 2019.10.7); from 2019.6.0, before 2019.6.14 (fixed in 2019.6.14); from 2019.9.0, before 2019.9.8 (fixed in 2019.9.8)

Published 2019-11-28. Last modified 2026-06-17.