First published: Thu Nov 19 2020(Updated: )
InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in `services/httpd/handler.go` because a JWT token may have an empty SharedSecret (aka shared secret).
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
go/github.com/influxdata/influxdb | <1.7.6 | 1.7.6 |
debian/influxdb | 1.6.4-1+deb10u1 1.6.7~rc0-1 1.6.7~rc0-2 | |
influxData influxDB | <1.7.6 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Debian | =9.0 | |
Debian | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.