=========================================================================Ubuntu Security Notice USN-5451-1
May 31, 2022

influxdb vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

An InfluxDB vulnerability allowed attackers to login as any known
database user.

Software Description:
- influxdb: Scalable datastore for metrics, events, and real-time analytics

Details:

Ilya Averyanov discovered that an InfluxDB vulnerability allowed
attackers to bypass authentication and gain access to any known
database user.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
influxdb 1.6.4-1+deb10u1build0.20.04.1

Ubuntu 18.04 LTS:
influxdb 1.1.1+dfsg1-4+deb9u1ubuntu1

After a standard system update you need to restart the influxdb
service to make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5451-1
CVE-2019-20933

Package Information:
https://launchpad.net/ubuntu/+source/influxdb/1.6.4-1+deb10u1build0.20.04.1
https://launchpad.net/ubuntu/+source/influxdb/1.1.1+dfsg1-4+deb9u1ubuntu1

Ubuntu 5451-1: InfluxDB vulnerability

May 31, 2022
An InfluxDB vulnerability allowed attackers to login as any known database user.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: influxdb 1.6.4-1+deb10u1build0.20.04.1 Ubuntu 18.04 LTS: influxdb 1.1.1+dfsg1-4+deb9u1ubuntu1 After a standard system update you need to restart the influxdb service to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5451-1

CVE-2019-20933

Severity
May 31, 2022

Package Information

https://launchpad.net/ubuntu/+source/influxdb/1.6.4-1+deb10u1build0.20.04.1 https://launchpad.net/ubuntu/+source/influxdb/1.1.1+dfsg1-4+deb9u1ubuntu1

Related News