Octopus Deploy · Octopus Deploy · CVE-2019-15507
**Name of the Vulnerable Software and Affected Versions**
Octopus Deploy versions 2018.8.4 through 2019.7.6
**Description**
The issue allows an authenticated user, under specific circumstances involving special characters, to trigger a deployment that writes the web request proxy password to the deployment log in cleartext when a web request proxy is configured.
**Recommendations**
For versions 2018.8.4 through 2019.7.6, update to version 2019.7.7 or later to resolve the issue.
For LTS versions, update to 2019.6.7 or 2019.3.8 to apply the back-ported fix.