Skip to content
influxdbGHSA-w55x-q3gv-px85

InfluxDB Reflected Cross-site Scripting

Medium4.8CVE-2018-17572 · Published May 24, 2022 · updated Feb 1, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
github.com/influxdata/influxdb
Go
< 0.9.60.9.6
Details and references

InfluxDB 0.9.5 has Reflected XSS in the admin panel via the Write Data module.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-79
Also known as
CVE-2018-17572

More influxdb advisories

All
DateAdvisory
May 182021Improper Authentication in InfluxDB
CVE-2019-20933Critical9.8fixed in 1.7.6

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.