Vulnerability Description
Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API because user supplied data in the API request isn’t parameterised correctly. Exploiting this vulnerability could allow unauthorised access to database tables.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Octopus | Server | >= 2018.9.17, < 2018.13.0 |
Related Weaknesses (CWE)
References
- https://advisories.octopus.com/adv/2021-04---SQL-Injection-in-the-Events-REST-AP
- https://advisories.octopus.com/adv/2021-04---SQL-Injection-in-the-Events-REST-AP
FAQ
What is CVE-2021-31818?
CVE-2021-31818 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API because user supplied data in the API request isn’t parameterised correctly. Exploi...
How severe is CVE-2021-31818?
CVE-2021-31818 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-31818?
Check the references section above for vendor advisories and patch information. Affected products include: Octopus Server.