Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API because user supplied data in the API request isn’t parameterised correctly. Exploiting this vulnerability could allow unauthorised access to database tables.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: Octopus
Published: 2021-06-17T13:22:17
Updated: 2024-08-03T23:10:30.820Z
Reserved: 2021-04-26T00:00:00
Link: CVE-2021-31818

No data.

Status : Modified
Published: 2021-06-17T14:15:08.173
Modified: 2024-11-21T06:06:17.563
Link: CVE-2021-31818

No data.