Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API because user supplied data in the API request isn’t parameterised correctly. Exploiting this vulnerability could allow unauthorised access to database tables.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Octopus

Published: 2021-06-17T13:22:17

Updated: 2024-08-03T23:10:30.820Z

Reserved: 2021-04-26T00:00:00

Link: CVE-2021-31818

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-06-17T14:15:08.173

Modified: 2023-11-07T03:35:00.873

Link: CVE-2021-31818

cve-icon Redhat

No data.