CVE-2024-9194

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Linux and Microsoft Windows Octopus Server on Windows, Linux allows SQL Injection.This issue affects Octopus Server: from 2024.1.0 before 2024.1.13038, from 2024.2.0 before 2024.2.9482, from 2024.3.0 before 2024.3.12766.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:*
cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:*
cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

02 Jul 2025, 17:25

Type Values Removed Values Added
CPE cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
References () https://advisories.octopus.com/post/2024/sa2024-09/ - () https://advisories.octopus.com/post/2024/sa2024-09/ - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Octopus
Linux
Microsoft windows
Octopus octopus Server
Microsoft
Linux linux Kernel

30 Sep 2024, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-30 23:15

Updated : 2025-07-02 17:25


NVD link : CVE-2024-9194

Mitre link : CVE-2024-9194


JSON object : View

Products Affected

linux

  • linux_kernel

microsoft

  • windows

octopus

  • octopus_server
CWE

No CWE.