In Octopus Deploy 3.3.0 through 2019.10.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted package, triggering an exception that exposes underlying operating system details.
References
Link | Resource |
---|---|
https://github.com/OctopusDeploy/Issues/issues/5971 | Third Party Advisory |
Configurations
Information
Published : 2019-11-18 08:15
Updated : 2019-11-20 13:17
NVD link : CVE-2019-19084
Mitre link : CVE-2019-19084
JSON object : View
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
Products Affected
octopus
- octopus_deploy