PT-2022-23525 · Influxdb+2 · Influxdb+2

Published

2020-04-21

·

Updated

2024-08-03

·

CVE-2022-36640

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions influxDB versions prior to 1.8.10
Description The issue concerns the lack of an authentication mechanism or controls in influxDB, allowing unauthenticated attackers to execute arbitrary commands. This could potentially expose data to any unauthenticated user if the database is deployed on a publicly accessible endpoint.
Recommendations For versions prior to 1.8.10, update to version 1.8.10 or later to enable authentication and authorization mechanisms, thereby preventing unauthenticated access and command execution. As a temporary workaround, consider restricting access to the influxDB instance to minimize the risk of exploitation until the update can be applied.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1824
ALT-PU-2020-3347
ALT-PU-2022-1251
BIT-INFLUXDB-2022-36640
CVE-2022-36640

Affected Products

Alt Linux
Debian
Influxdb