Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API because user supplied data in the API request isn’t parameterised correctly. Exploiting this vulnerability could allow unauthorised access to database tables.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Octopus
Published: 2021-06-17T13:22:17
Updated: 2024-08-03T23:10:30.820Z
Reserved: 2021-04-26T00:00:00
Link: CVE-2021-31818
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-06-17T14:15:08.173
Modified: 2024-11-21T06:06:17.563
Link: CVE-2021-31818
Redhat
No data.