Skip to content
influxdbGHSA-2rmp-fw5r-j5qv

Improper Authentication in InfluxDB

Critical9.8CVE-2019-20933 · Published May 18, 2021 · updated Aug 21, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/influxdata/influxdb
Go
< 1.7.61.7.6
Details and references

InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in `services/httpd/handler.go` because a JWT token may have an empty SharedSecret (aka shared secret).

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-287
Also known as
CVE-2019-20933, GO-2022-0780

More influxdb advisories

All
DateAdvisory
May 242022InfluxDB Reflected Cross-site Scripting
CVE-2018-17572Medium4.8fixed in 0.9.6

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.