5.3
CVE-2019-19375
- EPSS 0.42%
- Veröffentlicht 28.11.2019 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:34:40
- CVE-Watchlists
- Unerledigt
In Octopus Deploy before 2019.10.7, in a configuration where SSL offloading is enabled, the CSRF cookie was sometimes sent without the secure attribute. (The fix for this was backported to LTS versions 2019.6.14 and 2019.9.8.)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Octopus ≫ Octopus Deploy SwEdition- Version < 2019.10.7
Octopus ≫ Octopus Deploy SwEditionlts Version >= 2019.6.0 < 2019.6.14
Octopus ≫ Octopus Deploy SwEditionlts Version >= 2019.9.0 < 2019.9.8
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.42% | 0.335 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
https://github.com/OctopusDeploy/Issues/issues/5998