← Back

CVE-2021-31818

nvd nist
Published: Jun 17, 2021Modified: Nov 21, 2024

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API because user supplied data in the API request isn’t parameterised correctly. Exploiting this vulnerability could allow unauthorised access to database tables.

Affected (4)

Products: Octopus: Server
1 product
Server
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Octopus
From 2018.9.17 to 2018.13.0
From 2020.0.0 to 2020.6.0
From 2020.6.0 to 2020.6.5146
From 2021.1.0 to 2021.1.7316

Timeline

No history available yet.