Skip to content
Noroxi

influxdata records

5 published records for vendor influxdata.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
40%
Median publish → KEV
No record has entered KEV

All records

5 records
  • InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT tok

    CriticalCVSS 9.8Proof of conceptEPSS 31%

    influxdata · influxdbNov 18, 2020

  • influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary

    CriticalCVSS 9.8No exploitEPSS 3%

    influxdata · influxdbSep 2, 2022

  • The official telegraf docker images before 1.9.4-alpine (Alpine specific) contain a blank password for a root user.

    CriticalCVSS 9.8No exploitEPSS 2%

    influxdata · telegrafDec 16, 2020

  • InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with r

    CriticalCVSS 9.1Proof of conceptEPSS 5%

    Nov 21, 2024

  • InfluxDB 0.9.5 has Reflected XSS in the Write Data module.

    MediumCVSS 4.8No exploitEPSS 1%

    influxdata · influxdbMar 2, 2020