FlawAtlas
Search the atlas
CVE-2019-20933 Critical

Improper Authentication in InfluxDB in github.com/influxdata/influxdb

Improper Authentication in InfluxDB in github.com/influxdata/influxdb

Exploit probability 30.9%
Published August 21, 2024
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

145 explicit affected versions

Go github.com/influxdata/influxdb
Go github.com/influxdata/influxdb

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2019-20933

InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT token may have an empty SharedSecret (aka shared secret).

View original source
Open Source Vulnerabilities GO-2022-0780

Improper Authentication in InfluxDB in github.com/influxdata/influxdb

View original source
Open Source Vulnerabilities GHSA-2rmp-fw5r-j5qv

InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in `services/httpd/handler.go` because a JWT token may have an empty SharedSecret (aka shared secret).

View original source

05 / REFERENCES

Further evidence