Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-36640

Опубликовано: 02 сент. 2022
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands. NOTE: the CVE ID assignment is disputed because the vendor's documentation states "If InfluxDB is being deployed on a publicly accessible endpoint, we strongly recommend authentication be enabled. Otherwise the data will be publicly available to any unauthenticated user. The default settings do NOT enable authentication and authorization.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:influxdata:influxdb:*:*:*:*:*:*:*:*
Версия до 1.8.0 (исключая)

EPSS

Процентиль: 92%
0.08161
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 3 лет назад

influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands. NOTE: the CVE ID assignment is disputed because the vendor's documentation states "If InfluxDB is being deployed on a publicly accessible endpoint, we strongly recommend authentication be enabled. Otherwise the data will be publicly available to any unauthenticated user. The default settings do NOT enable authentication and authorization.

CVSS3: 9.8
debian
больше 3 лет назад

influxData influxDB before v1.8.10 contains no authentication mechanis ...

CVSS3: 9.8
github
больше 3 лет назад

influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands.

EPSS

Процентиль: 92%
0.08161
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-276