CVE-2021-31818

Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API because user supplied data in the API request isn’t parameterised correctly. Exploiting this vulnerability could allow unauthorised access to database tables.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:octopus:server:*:*:*:*:*:*:*:*
cpe:2.3:a:octopus:server:*:*:*:*:*:*:*:*
cpe:2.3:a:octopus:server:*:*:*:*:*:*:*:*
cpe:2.3:a:octopus:server:*:*:*:*:*:*:*:*

History

07 Nov 2023, 03:35

Type Values Removed Values Added
References
  • {'url': 'https://advisories.octopus.com/adv/2021-04---SQL-Injection-in-the-Events-REST-API-(CVE-2021-31818).2013233248.html', 'name': 'https://advisories.octopus.com/adv/2021-04---SQL-Injection-in-the-Events-REST-API-(CVE-2021-31818).2013233248.html', 'tags': ['Vendor Advisory'], 'refsource': 'MISC'}
  • () https://advisories.octopus.com/adv/2021-04---SQL-Injection-in-the-Events-REST-API-%28CVE-2021-31818%29.2013233248.html -

21 Jun 2021, 19:36

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 4.0
v3 : 4.3
References (MISC) https://advisories.octopus.com/adv/2021-04---SQL-Injection-in-the-Events-REST-API-(CVE-2021-31818).2013233248.html - (MISC) https://advisories.octopus.com/adv/2021-04---SQL-Injection-in-the-Events-REST-API-(CVE-2021-31818).2013233248.html - Vendor Advisory
CPE cpe:2.3:a:octopus:server:*:*:*:*:*:*:*:*
CWE CWE-89

17 Jun 2021, 14:20

Type Values Removed Values Added
New CVE

Information

Published : 2021-06-17 14:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-31818

Mitre link : CVE-2021-31818

CVE.ORG link : CVE-2021-31818


JSON object : View

Products Affected

octopus

  • server
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')