Generated remediation guidance and an executive summary. No account required.
influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands. NOTE: the CVE ID assignment is disputed because the vendor's documentation states "If InfluxDB is being deployed on a publicly accessible endpoint, we strongly recommend authentication be enabled. Otherwise the data will be publicly available to any unauthenticated user. The default settings do NOT enable authentication and authorization.
Use CWE-276, Influxdata vendor hub and Influxdb product page to widen CVE-2022-36640 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-20933 and CVE-2018-17572 for nearby disclosures in the same product family.