Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API because user supplied data in the API request isn’t parameterised correctly. Exploiting this vulnerability could allow unauthorised access to database tables.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-18694 | Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API because user supplied data in the API request isn’t parameterised correctly. Exploiting this vulnerability could allow unauthorised access to database tables. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: Octopus
Published:
Updated: 2024-08-03T23:10:30.820Z
Reserved: 2021-04-26T00:00:00
Link: CVE-2021-31818
No data.
Status : Modified
Published: 2021-06-17T14:15:08.173
Modified: 2024-11-21T06:06:17.563
Link: CVE-2021-31818
No data.
OpenCVE Enrichment
No data.
EUVD