CVE-2019-20933

CRITICAL9.8EPSS 93.7%

Improper Authentication in InfluxDB

發布日:2021/5/18修改日:2024/8/21
也稱為:GHSA-2rmp-fw5r-j5qvDEBIAN-CVE-2019-20933GO-2022-0780

描述

InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in `services/httpd/handler.go` because a JWT token may have an empty SharedSecret (aka shared secret).

受影響套件(5)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

參考連結(10)