Записи influxdata
5 опубликованных записей вендора influxdata.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 40 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-276 Incorrect Default Permissions1
- CWE-287 Improper Authentication1
- CWE-306 Missing Authentication for Critical Function1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-922 Insecure Storage of Sensitive Information1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
5 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
48В плане | CVE-2019-20933Proof of concept | InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT tokinfluxdata · influxdb · CWE-287 | Критическая9,8 | — | 30,9 % | 18 нояб. 2020 г. |
40В плане | CVE-2022-36640Эксплойта нет | influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitraryinfluxdata · influxdb · CWE-276 | Критическая9,8 | — | 2,5 % | 2 сент. 2022 г. |
40В плане | CVE-2020-35187Эксплойта нет | The official telegraf docker images before 1.9.4-alpine (Alpine specific) contain a blank password for a root user.influxdata · telegraf · CWE-306 | Критическая9,8 | — | 2,2 % | 16 дек. 2020 г. |
38Наблюдать | CVE-2024-30896Proof of concept | InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with rCWE-922 | Критическая9,1 | — | 5,4 % | 21 нояб. 2024 г. |
19Наблюдать | CVE-2018-17572Эксплойта нет | InfluxDB 0.9.5 has Reflected XSS in the Write Data module.influxdata · influxdb · CWE-79 | Средняя4,8 | — | 0,7 % | 2 мар. 2020 г. |
- CVE-2019-2093348В плане
InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT tok
КритическаяCVSS 9,8Proof of conceptEPSS 31 %influxdata · influxdb18 нояб. 2020 г.
- CVE-2022-3664040В плане
influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %influxdata · influxdb2 сент. 2022 г.
- CVE-2020-3518740В плане
The official telegraf docker images before 1.9.4-alpine (Alpine specific) contain a blank password for a root user.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %influxdata · telegraf16 дек. 2020 г.
- CVE-2024-3089638Наблюдать
InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with r
КритическаяCVSS 9,1Proof of conceptEPSS 5 %21 нояб. 2024 г.
- CVE-2018-1757219Наблюдать
InfluxDB 0.9.5 has Reflected XSS in the Write Data module.
СредняяCVSS 4,8Эксплойта нетEPSS 1 %influxdata · influxdb2 мар. 2020 г.