5.3
CVE-2019-19375
- EPSS 0.17%
- Veröffentlicht 28.11.2019 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:34:40
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
In Octopus Deploy before 2019.10.7, in a configuration where SSL offloading is enabled, the CSRF cookie was sometimes sent without the secure attribute. (The fix for this was backported to LTS versions 2019.6.14 and 2019.9.8.)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Octopus ≫ Octopus Deploy SwEdition- Version < 2019.10.7
Octopus ≫ Octopus Deploy SwEditionlts Version >= 2019.6.0 < 2019.6.14
Octopus ≫ Octopus Deploy SwEditionlts Version >= 2019.9.0 < 2019.9.8
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.383 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.