Influxdata Influxdb vulnerabilities
3 known vulnerabilities affecting influxdata/influxdb.
Total CVEs
3
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2022-36640CRITICALCVSS 9.8fixed in 1.8.02022-09-02
CVE-2022-36640 [CRITICAL] CWE-276 CVE-2022-36640: influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauth
influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands. NOTE: the CVE ID assignment is disputed because the vendor's documentation states "If InfluxDB is being deployed on a publicly accessible endpoint, we strongly recommend authentication be enabled. O
nvd
CVE-2019-20933CRITICALCVSS 9.8PoCfixed in 1.7.62020-11-19
CVE-2019-20933 [CRITICAL] CWE-287 CVE-2019-20933: InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in ser
InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT token may have an empty SharedSecret (aka shared secret).
nvdosv
CVE-2018-17572MEDIUMCVSS 4.8≤ 0.9.52020-03-02
CVE-2018-17572 [MEDIUM] CWE-79 CVE-2018-17572: InfluxDB 0.9.5 has Reflected XSS in the Write Data module.
InfluxDB 0.9.5 has Reflected XSS in the Write Data module.
nvdosv