Influxdata
Influxdata Influxdb: vulnerabilities and CVEs
Influxdata Influxdb has 3 published vulnerabilities, 0 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs3
Last 12 months0
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36640 | Critical (9.8) | 2.5% | — | Sep 2, 2022 | influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands. NOTE: the CVE ID assignment is disputed because the vendor's… |
| CVE-2019-20933 | Critical (9.8) | 31% | — | Nov 19, 2020 | InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT token may have an empty SharedSecret (aka shared secret). |
| CVE-2018-17572 | Medium (4.8) | 0.73% | — | Mar 2, 2020 | InfluxDB 0.9.5 has Reflected XSS in the Write Data module. |