InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with read access to the authorization resource of the default organization to retrieve the operator token. InfluxDB OSS 1.x, Enterprise, Cloud, Cloud Dedicated and Clustered are not affected. NOTE: The researcher states that InfluxDB allows allAccess administrators to retrieve all raw tokens via an "influx auth ls" command. The supplier indicates that the organizations feature is operating as intended and that users may choose to add users to non-default organizations. A future release of InfluxDB 2.x will remove the ability to retrieve tokens from the API.
History

Tue, 03 Dec 2024 21:15:00 +0000

Type Values Removed Values Added
Description InfluxDB through 2.7.10 allows allAccess administrators to retrieve all raw tokens via an "influx auth ls" command. NOTE: the supplier indicates that this is intentional but is a "poor design choice" that will be changed in a future release. InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with read access to the authorization resource of the default organization to retrieve the operator token. InfluxDB OSS 1.x, Enterprise, Cloud, Cloud Dedicated and Clustered are not affected. NOTE: The researcher states that InfluxDB allows allAccess administrators to retrieve all raw tokens via an "influx auth ls" command. The supplier indicates that the organizations feature is operating as intended and that users may choose to add users to non-default organizations. A future release of InfluxDB 2.x will remove the ability to retrieve tokens from the API.

Wed, 27 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Influxdata
Influxdata influxdb
Weaknesses CWE-922
CPEs cpe:2.3:a:influxdata:influxdb:*:*:*:*:*:*:*:*
Vendors & Products Influxdata
Influxdata influxdb
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 26 Nov 2024 03:00:00 +0000

Type Values Removed Values Added
Title InfluxDB: Privilege Escalation via Authorization Token in InfluxDB
References
Metrics threat_severity

None

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}

threat_severity

Important


Thu, 21 Nov 2024 04:15:00 +0000

Type Values Removed Values Added
Description InfluxDB through 2.7.10 allows allAccess administrators to retrieve all raw tokens via an "influx auth ls" command. NOTE: the supplier indicates that this is intentional but is a "poor design choice" that will be changed in a future release.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-11-21T00:00:00

Updated: 2024-12-03T21:03:13.616920

Reserved: 2024-03-27T00:00:00

Link: CVE-2024-30896

cve-icon Vulnrichment

Updated: 2024-11-27T16:24:43.160Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-21T11:15:34.007

Modified: 2024-12-03T21:15:06.437

Link: CVE-2024-30896

cve-icon Redhat

Severity : Important

Publid Date: 2024-11-21T00:00:00Z

Links: CVE-2024-30896 - Bugzilla