CVE-2019-20933 is a critical authentication bypass vulnerability affecting InfluxDB versions prior to 1.7.6, stemming from an empty shared secret in JWT token authentication. With a CVSS score of 9.8, it allows unauthenticated attackers to achieve full compromise (confidentiality, integrity, availability) over the network with low complexity. While not listed in CISA KEV and lacking Metasploit/ExploitDB entries, Nuclei templates exist for exploitation, and its high EPSS score suggests a significant likelihood of future exploitation, despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.7.6CPE matchmatch criteria | cpe:2.3:a:influxdata:influxdb:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.