influxdata records
5 published records for vendor influxdata.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 40%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-276 Incorrect Default Permissions1
- CWE-287 Improper Authentication1
- CWE-306 Missing Authentication for Critical Function1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-922 Insecure Storage of Sensitive Information1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
48Plan | CVE-2019-20933Proof of concept | InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT tokinfluxdata · influxdb · CWE-287 | Critical9.8 | — | 30.9% | Nov 18, 2020 |
40Plan | CVE-2022-36640No exploit | influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitraryinfluxdata · influxdb · CWE-276 | Critical9.8 | — | 2.5% | Sep 2, 2022 |
40Plan | CVE-2020-35187No exploit | The official telegraf docker images before 1.9.4-alpine (Alpine specific) contain a blank password for a root user.influxdata · telegraf · CWE-306 | Critical9.8 | — | 2.2% | Dec 16, 2020 |
38Monitor | CVE-2024-30896Proof of concept | InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with rCWE-922 | Critical9.1 | — | 5.4% | Nov 21, 2024 |
19Monitor | CVE-2018-17572No exploit | InfluxDB 0.9.5 has Reflected XSS in the Write Data module.influxdata · influxdb · CWE-79 | Medium4.8 | — | 0.7% | Mar 2, 2020 |
- CVE-2019-2093348Plan
InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT tok
CriticalCVSS 9.8Proof of conceptEPSS 31%influxdata · influxdbNov 18, 2020
- CVE-2022-3664040Plan
influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary
CriticalCVSS 9.8No exploitEPSS 3%influxdata · influxdbSep 2, 2022
- CVE-2020-3518740Plan
The official telegraf docker images before 1.9.4-alpine (Alpine specific) contain a blank password for a root user.
CriticalCVSS 9.8No exploitEPSS 2%influxdata · telegrafDec 16, 2020
- CVE-2024-3089638Monitor
InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with r
CriticalCVSS 9.1Proof of conceptEPSS 5%Nov 21, 2024
- CVE-2018-1757219Monitor
InfluxDB 0.9.5 has Reflected XSS in the Write Data module.
MediumCVSS 4.8No exploitEPSS 1%influxdata · influxdbMar 2, 2020