CVE-2024-9194

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Linux and Microsoft Windows Octopus Server on Windows, Linux allows SQL Injection.This issue affects Octopus Server: from 2024.1.0 before 2024.1.13038, from 2024.2.0 before 2024.2.9482, from 2024.3.0 before 2024.3.12766.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:*
cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:*
cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

02 Jul 2025, 17:25

Type Values Removed Values Added
References () https://advisories.octopus.com/post/2024/sa2024-09/ - () https://advisories.octopus.com/post/2024/sa2024-09/ - Vendor Advisory
First Time Octopus octopus Server
Linux
Microsoft
Octopus
Microsoft windows
Linux linux Kernel
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:octopus:octopus_server:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

Information

Published : 2024-09-30 23:15

Updated : 2025-07-02 17:25


NVD link : CVE-2024-9194

Mitre link : CVE-2024-9194

CVE.ORG link : CVE-2024-9194


JSON object : View

Products Affected

microsoft

  • windows

octopus

  • octopus_server

linux

  • linux_kernel
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')