-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability exists in the admin panel's Write Data module where user input is reflected without proper sanitization. While exact patch details are unavailable, the standard InfluxDB architecture places HTTP handlers in services/httpd. The serveWrite handler would process write operations, and serveAdmin would handle admin interface routing. These functions would appear in stack traces when processing malicious payloads in write requests. Confidence is medium due to indirect evidence from vulnerability descriptions and typical Go web application patterns.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/influxdata/influxdb | go | <= 0.9.5 | 0.9.6 |
Ongoing coverage of React2Shell