Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-36640
HistorySep 02, 2022 - 9:15 p.m.

Authorization

2022-09-0221:15:00
PRIOn knowledge base
www.prio-n.com
12
influxdata
influxdb
authentication mechanism
unauthenticated attackers
arbitrary commands
cve id
vendor's documentation

9.8 High

AI Score

Confidence

High

0.008 Low

EPSS

Percentile

81.7%

DISPUTED influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands. NOTE: the CVE ID assignment is disputed because the vendor’s documentation states “If InfluxDB is being deployed on a publicly accessible endpoint, we strongly recommend authentication be enabled. Otherwise the data will be publicly available to any unauthenticated user. The default settings do NOT enable authentication and authorization.”

CPENameOperatorVersion
influxdblt1.8.0

9.8 High

AI Score

Confidence

High

0.008 Low

EPSS

Percentile

81.7%

Related for PRION:CVE-2022-36640