« Volver al listado

CVE-2021-31818

Estado: ModificadaMedia (4.3)—

Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API because user supplied data in the API request isn’t parameterised correctly. Exploiting this vulnerability could allow unauthorised access to database tables.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-31818",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@octopus.com",
      "affectedData": [
        {
          "vendor": "Octopus Deploy",
          "product": "Octopus Server",
          "versions": [
            {
              "status": "affected",
              "version": "2018.9.17",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "2020.6.5146",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "2021.1.7149",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "2021.1.7316",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-06-17T14:15:08.173",
  "references": [
    {
      "url": "https://advisories.octopus.com/adv/2021-04---SQL-Injection-in-the-Events-REST-API-%28CVE-2021-31818%29.2013233248.html",
      "source": "security@octopus.com"
    },
    {
      "url": "https://advisories.octopus.com/adv/2021-04---SQL-Injection-in-the-Events-REST-API-%28CVE-2021-31818%29.2013233248.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API because user supplied data in the API request isn’t parameterised correctly. Exploiting this vulnerability could allow unauthorised access to database tables."
    },
    {
      "lang": "es",
      "value": "Unas versiones afectadas de Octopus Server son propensas a una vulnerabilidad de inyección SQL autenticada en la interfaz Events REST API porque los datos suministrados por el usuario en la petición de la API no están parametrizados correctamente. Una explotación de esta vulnerabilidad podría permitir un acceso no autorizado a las tablas de la base de datos"
    }
  ],
  "lastModified": "2026-06-17T03:52:17.630",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:octopus:server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D5B45498-7438-4ED2-9C49-EBAB78D76894",
              "versionEndExcluding": "2018.13.0",
              "versionStartIncluding": "2018.9.17"
            },
            {
              "criteria": "cpe:2.3:a:octopus:server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "65924664-F273-49EB-AF50-8D516472F17E",
              "versionEndExcluding": "2020.6.0",
              "versionStartIncluding": "2020.0.0"
            },
            {
              "criteria": "cpe:2.3:a:octopus:server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "035EA471-8FDD-485A-BC94-0BACBE718EEB",
              "versionEndExcluding": "2020.6.5146",
              "versionStartIncluding": "2020.6.0"
            },
            {
              "criteria": "cpe:2.3:a:octopus:server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DFC37FF8-2A15-4BD5-888D-FC2AF802535C",
              "versionEndExcluding": "2021.1.7316",
              "versionStartIncluding": "2021.1.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@octopus.com"
}