influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands. NOTE: the CVE ID assignment is disputed because the vendor's documentation states "If InfluxDB is being deployed on a publicly accessible endpoint, we strongly recommend authentication be enabled. Otherwise the data will be publicly available to any unauthenticated user. The default settings do NOT enable authentication and authorization.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-09-02T20:50:45
Updated: 2024-08-03T10:07:34.545Z
Reserved: 2022-07-25T00:00:00
Link: CVE-2022-36640
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-09-02T21:15:16.427
Modified: 2024-11-21T07:13:27.050
Link: CVE-2022-36640
Redhat
No data.