Description
Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API because user supplied data in the API request isn’t parameterised correctly. Exploiting this vulnerability could allow unauthorised access to database tables.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-18694 | Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API because user supplied data in the API request isn’t parameterised correctly. Exploiting this vulnerability could allow unauthorised access to database tables. |
References
History
No history.
Status: PUBLISHED
Assigner: Octopus
Published:
Updated: 2024-08-03T23:10:30.820Z
Reserved: 2021-04-26T00:00:00.000Z
Link: CVE-2021-31818
No data.
Status : Modified
Published: 2021-06-17T14:15:08.173
Modified: 2024-11-21T06:06:17.563
Link: CVE-2021-31818
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD