CVE-2021-31818: SQL Injection

Published Jun 17, 2021
·
Updated

Affected versions of Octopus Server are prone to an authenticated SQL injection vulnerability in the Events REST API because user supplied data in the API request isn’t parameterised correctly. Exploiting this vulnerability could allow unauthorised access to database tables.

Affected Software

4 affected components
Octopus Server>=2018.9.17<2018.13.0
Octopus Server>=2020.0.0<2020.6.0
Octopus Server>=2020.6.0<2020.6.5146
Octopus Server>=2021.1.0<2021.1.7316

Event History

Jun 17, 2021
CVE Published
via MITRE·01:22 PM
Data Sourced
via MITRE·01:22 PM
DescriptionWeakness

Frequently Asked Questions

1

What is the severity of CVE-2021-31818?

CVE-2021-31818 is considered a critical severity vulnerability due to the potential for unauthorized database access.

2

How do I fix CVE-2021-31818?

To fix CVE-2021-31818, upgrade Octopus Server to a version that contains the patch for the SQL injection vulnerability.

3

What versions are affected by CVE-2021-31818?

CVE-2021-31818 affects Octopus Server versions between 2018.9.17 and 2018.13.0, 2020.0.0 and 2020.6.0, 2020.6.0 and 2020.6.5146, and 2021.1.0 and 2021.1.7316.

4

How can CVE-2021-31818 be exploited?

CVE-2021-31818 can be exploited by using specially crafted user input in the Events REST API to execute unauthorized SQL queries.

5

Who is affected by CVE-2021-31818?

Organizations using the affected versions of Octopus Server are at risk of CVE-2021-31818 and should take immediate action to mitigate the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203