InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT token may have an empty SharedSecret (aka shared secret).
| Software | From | Fixed in |
|---|---|---|
| influxdata / influxdb | - | 1.7.6 |
| debian / debian_linux | 9.0 | 9.0.x |
| debian / debian_linux | 10.0 | 10.0.x |
github.com/influxdata/influxdb/services/httpd
|
- | 1.7.6 |