Back

CRITICAL

influxdb: authentication bypass because a JWT token may have an empty SharedSecret

Published Nov 19, 2020

Description

InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT token may have an empty SharedSecret (aka shared secret).

Affected products

Remediation

Red Hat mitigation

For versions before 1.7.6, as per the documentation updated by influxdb, ensure that a default shared-secret has be defined when enabling JWT authentication: https://docs.influxdata.com/influxdb/v1.8/administration/authentication_and_authorization/#1-add-a-shared-secret-in-your-influxdb-configuration-file Versions including the fix will return an error if the secret is left empty.

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 19, 2020
Updated Aug 5, 2024
Reserved Nov 19, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Mar 27, 2019
GHSA-2RMP-FW5R-J5QV