Critical
CVE-2019-20933
PUBLISHEDInfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT token may...
Not yet in CISA KEV
- Vendor
- InfluxData
- Product
- InfluxDB
- Published
- Nov 19, 2020
- EPSS
- —
Automate This Intelligence with the Pro API
Everything on this page — CVSS, EPSS, exploit status, PoCs, scanner integrations, mentions, tags, and immediate honeypot data — is available programmatically for VM, SOC, and CTI workflows.
Description
InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT token may have an empty SharedSecret (aka shared secret).
CVSS Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitation Status
Proof of concept available
Recorded 2021-04-28 16:25:31 UTC · GitHub
References
- https://github.com/influxdata/influxdb/issues/12927
- https://github.com/influxdata/influxdb/compare/v1.7.5...v1.7.6
- https://github.com/influxdata/influxdb/commit/761b557315ff9c1642cf3b0e5797cd3d983a24c0
- https://lists.debian.org/debian-lts-announce/2020/12/msg00030.html
- https://www.debian.org/security/2021/dsa-4823
Known Exploited Vulnerability Sources
Catalogues that list this CVE as a known exploited vulnerability.
| Source | Added |
|---|---|
| The Shadowserver (via CIRCL) First | 2025-07-01 00:00 UTC |
Scanner Integrations
| Scanner | Reference | Detected |
|---|---|---|
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2019/CVE-2019-20933.yaml | Apr 25, 2025 |
Potential Proof of Concepts
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2021-07-24 11:12:13 UTC · 1 stars
github · Created 2021-04-28 16:25:31 UTC · 39 stars
InfluxDB CVE-2019-20933 vulnerability exploit
nuclei · Created Unknown
Timeline
-
Added to KEVIntel
-
Detected by Nuclei
-
Proof of Concept Exploit Available
-
CVE Published to Public
-
CVE ID Reserved