InfluxDB before 1.7.6 contains an authentication bypass vulnerability via the authenticate function in services/httpd/handler.go. A JWT token may have an empty SharedSecret (aka shared secret). An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.
View the template here CVE-2019-20933.yaml
Lab | Machine | Link |
---|---|---|
Hack The Box | Devzat | Go to Practice |
References:
https://nvd.nist.gov/vuln/detail/CVE-2019-20933