Security readout for executives and security teams
Plain-English summary
Octopus Deploy versions before 2019.10.7 could, in SSL offloading deployments, send the CSRF cookie without the Secure flag. That weakens protection intended to keep browser cookies off plain HTTP. Business risk is configuration-dependent and mainly concerns environments where Octopus traffic could be downgraded or exposed over HTTP.
Executive priority
Prioritize remediation where Octopus Deploy is internet-facing, used for production release control, or behind SSL offloading. The issue is not shown as actively exploited, but deployment tooling has high business sensitivity.
Technical view
The flaw affects Octopus Deploy before 2019.10.7 when SSL offloading is enabled. The CSRF cookie was sometimes emitted without the Secure attribute. Fixes were backported to LTS releases 2019.6.14 and 2019.9.8. No CVSS, CWE, or detailed affected CPE data is provided in the bundle.
Likely exposure
Exposure is likely limited to Octopus Deploy instances older than 2019.10.7, especially SSL offloading deployments. LTS deployments should verify they are at least 2019.6.14 or 2019.9.8.
Exploitation context
The provided sources do not report active exploitation, and the CVE is not listed as KEV. Practical risk depends on whether users can reach Octopus over insecure HTTP paths or hostile networks.
Researcher notes
Evidence is limited: severity, CVSS, CWE, and structured affected product data are missing. The description names Octopus Deploy and fixed versions, while the affected array is n/a. Verify exact product scope against vendor guidance.
Mitigation direction
- Upgrade Octopus Deploy to 2019.10.7 or later.
- For LTS branches, upgrade to 2019.6.14 or 2019.9.8 or later.
- Review Octopus vendor issue 5998 for release-specific guidance.
- Enforce HTTPS access and redirect or block plain HTTP paths.
- Verify reverse proxy and SSL offloading settings preserve secure cookie behavior.
Validation and detection
- Inventory all Octopus Deploy server versions.
- Identify deployments using SSL offloading or reverse proxies.
- Check browser Set-Cookie headers for the CSRF cookie Secure attribute.
- Confirm HTTP access is redirected or blocked.
- Validate LTS systems include the documented backported fix.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2019-19375 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://github.com/OctopusDeploy/Issues/issues/5998CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
