InfluxDB through 2.7.10 allows allAccess administrators to retrieve all raw tokens via an "influx auth ls" command. NOTE: the supplier indicates that this is intentional but is a "poor design choice" that will be changed in a future release.
History

Thu, 21 Nov 2024 04:15:00 +0000

Type Values Removed Values Added
Description InfluxDB through 2.7.10 allows allAccess administrators to retrieve all raw tokens via an "influx auth ls" command. NOTE: the supplier indicates that this is intentional but is a "poor design choice" that will be changed in a future release.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-11-21T00:00:00

Updated: 2024-11-21T04:11:37.686654

Reserved: 2024-03-27T00:00:00

Link: CVE-2024-30896

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.