{"id":"BIT-influxdb-2022-36640","details":"influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands. NOTE: the CVE ID assignment is disputed because the vendor's documentation states \"If InfluxDB is being deployed on a publicly accessible endpoint, we strongly recommend authentication be enabled. Otherwise the data will be publicly available to any unauthenticated user. The default settings do NOT enable authentication and authorization.\"","aliases":["CVE-2022-36640"],"modified":"2026-09-08T08:47:54.118837937Z","published":"2024-03-06T10:53:17.690Z","database_specific":{"severity":"Critical","cpes":["cpe:2.3:a:influxdata:influxdb:*:*:*:*:*:*:*:*"]},"references":[{"type":"WEB","url":"http://influxdata.com"},{"type":"WEB","url":"http://influxdb.com"},{"type":"WEB","url":"http://www.krsecu.com/CVE/409b5310045bd6b9a984a5fb63bd8786d5c5681a8ad5b1c815c84b2b90002ad7.docx"},{"type":"ADVISORY","url":"https://dl.influxdata.com/influxdb/releases/influxdb_1.8.10_amd64.deb"},{"type":"FIX","url":"https://portal.influxdata.com/downloads/"},{"type":"WEB","url":"https://www.influxdata.com/"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-36640"}],"affected":[{"package":{"name":"influxdb","ecosystem":"Bitnami","purl":"pkg:bitnami/influxdb"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.8.0"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/influxdb/BIT-influxdb-2022-36640.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}],"schema_version":"1.9.0"}