InfluxDB through 2.7.10 allows allAccess administrators to retrieve all raw tokens via an "influx auth ls" command. NOTE: the supplier indicates that this is intentional but is a "poor design choice" that will be changed in a future release.
Metrics
Affected Vendors & Products
References
History
Thu, 21 Nov 2024 04:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | InfluxDB through 2.7.10 allows allAccess administrators to retrieve all raw tokens via an "influx auth ls" command. NOTE: the supplier indicates that this is intentional but is a "poor design choice" that will be changed in a future release. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-11-21T00:00:00
Updated: 2024-11-21T04:11:37.686654
Reserved: 2024-03-27T00:00:00
Link: CVE-2024-30896
Vulnrichment
No data.
NVD
No data.
Redhat
No data.