Loading
Generated remediation guidance and an executive summary. No account required.
InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT token may have an empty SharedSecret (aka shared secret).
Use CWE-287, Influxdata vendor hub and Influxdb product page to widen CVE-2019-20933 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-36640 and CVE-2018-17572 for nearby disclosures in the same product family.