CVE-2024-9194

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Linux and Microsoft Windows Octopus Server on Windows, Linux allows SQL Injection.This issue affects Octopus Server: from 2024.1.0 before 2024.1.13038, from 2024.2.0 before 2024.2.9482, from 2024.3.0 before 2024.3.12766.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:*
cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:*
cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

02 Jul 2025, 17:25

Type Values Removed Values Added
First Time Linux linux Kernel
Microsoft
Linux
Microsoft windows
Octopus
Octopus octopus Server
CPE cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
References () https://advisories.octopus.com/post/2024/sa2024-09/ - () https://advisories.octopus.com/post/2024/sa2024-09/ - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

21 Nov 2024, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 4.3
v2 : unknown
v3 : unknown

01 Oct 2024, 15:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
Summary
  • (es) Vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando SQL ('Inyección SQL') en Linux y Microsoft Windows Octopus Server en Windows, Linux permite la inyección SQL. Este problema afecta a Octopus Server: desde 2024.1.0 antes de 2024.1.13038, desde 2024.2.0 antes de 2024.2.9482, desde 2024.3.0 antes de 2024.3.12766.

30 Sep 2024, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-30 23:15

Updated : 2025-07-02 17:25


NVD link : CVE-2024-9194

Mitre link : CVE-2024-9194

CVE.ORG link : CVE-2024-9194


JSON object : View

Products Affected

linux

  • linux_kernel

octopus

  • octopus_server

microsoft

  • windows
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')