CVE-2021-31818

Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API because user supplied data in the API request isn’t parameterised correctly. Exploiting this vulnerability could allow unauthorised access to database tables.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:octopus:server:*:*:*:*:*:*:*:*
cpe:2.3:a:octopus:server:*:*:*:*:*:*:*:*
cpe:2.3:a:octopus:server:*:*:*:*:*:*:*:*
cpe:2.3:a:octopus:server:*:*:*:*:*:*:*:*

Information

Published : 2021-06-17 07:15

Updated : 2022-07-27 10:20


NVD link : CVE-2021-31818

Mitre link : CVE-2021-31818


JSON object : View

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Advertisement

dedicated server usa

Products Affected

octopus

  • server