QID 982567
QID 982567: Go (go) Security Update for github.com/influxdata/influxdb/services/httpd (GHSA-2rmp-fw5r-j5qv)
InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT token may have an empty SharedSecret (aka shared secret).
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-2rmp-fw5r-j5qv for updates pertaining to this vulnerability.
Vendor References
- GHSA-2rmp-fw5r-j5qv -
github.com/advisories/GHSA-2rmp-fw5r-j5qv
CVEs related to QID 982567
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-2rmp-fw5r-j5qv | github.com/influxdata/influxdb/services/httpd |
|