VYPR

rpm package

suse/influxdb&distro=SUSE OpenStack Cloud 7

pkg:rpm/suse/influxdb&distro=SUSE%20OpenStack%20Cloud%207

Vulnerabilities (5)

  • CVE-2019-20933Nov 19, 2020
    affected < 1.2.4-5.1fixed 1.2.4-5.1

    InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT token may have an empty SharedSecret (aka shared secret).

  • CVE-2020-24303Oct 28, 2020
    affected < 1.2.4-5.1fixed 1.2.4-5.1

    Grafana before 7.1.0-beta 1 allows XSS via a query alias for the ElasticSearch datasource.

  • CVE-2020-26137Sep 29, 2020
    affected < 1.2.4-5.1fixed 1.2.4-5.1

    urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.

  • CVE-2019-9740Mar 13, 2019
    affected < 1.2.4-5.1fixed 1.2.4-5.1

    An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \r\n (specifically in the query string

  • CVE-2016-8611Jul 31, 2018
    affected < 1.2.4-5.1fixed 1.2.4-5.1

    A vulnerability was found in Openstack Glance. No limits are enforced within the Glance image service for both v1 and v2 `/images` API POST method for authenticated users, resulting in possible denial of service attacks through database table saturation.