{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-11T17:16:21.230","vulnerabilities":[{"cve":{"id":"CVE-2021-31818","sourceIdentifier":"security@octopus.com","published":"2021-06-17T14:15:08.173","lastModified":"2024-11-21T06:06:17.563","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API because user supplied data in the API request isn’t parameterised correctly. Exploiting this vulnerability could allow unauthorised access to database tables."},{"lang":"es","value":"Unas versiones afectadas de Octopus Server son propensas a una vulnerabilidad de inyección SQL autenticada en la interfaz Events REST API porque los datos suministrados por el usuario en la petición de la API no están parametrizados correctamente. Una explotación de esta vulnerabilidad podría permitir un acceso no autorizado a las tablas de la base de datos"}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-89"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:octopus:server:*:*:*:*:*:*:*:*","versionStartIncluding":"2018.9.17","versionEndExcluding":"2018.13.0","matchCriteriaId":"D5B45498-7438-4ED2-9C49-EBAB78D76894"},{"vulnerable":true,"criteria":"cpe:2.3:a:octopus:server:*:*:*:*:*:*:*:*","versionStartIncluding":"2020.0.0","versionEndExcluding":"2020.6.0","matchCriteriaId":"65924664-F273-49EB-AF50-8D516472F17E"},{"vulnerable":true,"criteria":"cpe:2.3:a:octopus:server:*:*:*:*:*:*:*:*","versionStartIncluding":"2020.6.0","versionEndExcluding":"2020.6.5146","matchCriteriaId":"035EA471-8FDD-485A-BC94-0BACBE718EEB"},{"vulnerable":true,"criteria":"cpe:2.3:a:octopus:server:*:*:*:*:*:*:*:*","versionStartIncluding":"2021.1.0","versionEndExcluding":"2021.1.7316","matchCriteriaId":"DFC37FF8-2A15-4BD5-888D-FC2AF802535C"}]}]}],"references":[{"url":"https://advisories.octopus.com/adv/2021-04---SQL-Injection-in-the-Events-REST-API-%28CVE-2021-31818%29.2013233248.html","source":"security@octopus.com"},{"url":"https://advisories.octopus.com/adv/2021-04---SQL-Injection-in-the-Events-REST-API-%28CVE-2021-31818%29.2013233248.html","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}