Known Vulnerabilities for products from Influxdata
Listed below are 4 of the newest known vulnerabilities associated with the vendor "Influxdata".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-36640 json | influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to ex... | Not Provided | 2022-09-02 | 2026-07-09 |
| CVE-2020-35187 json | The official telegraf docker images before 1.9.4-alpine (Alpine specific) contain a blank password for a root user. System us... | 9.8 - CRITICAL | 2020-12-17 | 2020-12-17 |
| CVE-2019-20933 json | InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go be... | 9.8 - CRITICAL | 2020-11-19 | 2022-10-19 |
| CVE-2018-17572 json | InfluxDB 0.9.5 has Reflected XSS in the Write Data module. | 4.8 - MEDIUM | 2020-03-02 | 2020-03-03 |
Known software with vulnerabilities from Influxdata
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Influxdata | Chronograf Docker Image | 1.3.9.0 |
| Application | Influxdata | Influxdb | - |
| Application | Influxdata | Influxdb Docker Image | 1.0.0 |
| Application | Influxdata | Kapacitor Docker Image | - |
| Application | Influxdata | Telegraf Docker Image | 0.13.0 |