Medium severity6.5NVD Advisory· Published Nov 28, 2019· Updated Jun 17, 2026
CVE-2019-19376
CVE-2019-19376
Description
In Octopus Deploy before 2019.10.6, an authenticated user with TeamEdit permission could send a malformed Team API request that bypasses input validation and causes an application level denial of service condition. (The fix for this was also backported to LTS 2019.9.8 and LTS 2019.6.14.)
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:octopus:octopus_deploy:*:*:*:*:-:*:*:*+ 2 more
- cpe:2.3:a:octopus:octopus_deploy:*:*:*:*:-:*:*:*range: <2019.10.7
- cpe:2.3:a:octopus:octopus_deploy:*:*:*:*:lts:*:*:*range: >=2019.6.0,<2019.6.14
- (no CPE)range: <2019.10.6, LTS 2019.9.8, LTS 2019.6.14
- Octopus Deploy/Octopus Deploydescription
Patches
Vulnerability mechanics
References
1- github.com/OctopusDeploy/Issues/issues/6005nvdThird Party Advisory
News mentions
0No linked articles in our index yet.