influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands. NOTE: the CVE ID assignment is disputed because the vendor's documentation states "If InfluxDB is being deployed on a publicly accessible endpoint, we strongly recommend authentication be enabled. Otherwise the data will be publicly available to any unauthenticated user. The default settings do NOT enable authentication and authorization.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-09-02T20:50:45

Updated: 2024-08-03T10:07:34.545Z

Reserved: 2022-07-25T00:00:00

Link: CVE-2022-36640

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-09-02T21:15:16.427

Modified: 2024-08-03T10:15:50.070

Link: CVE-2022-36640

cve-icon Redhat

No data.