InfluxDB versions prior to 1.7.6 contain an authentication bypass vulnerability in the authenticate function within services/httpd/handler.go. The vulnerability arises because the JWT token validation process allows for an empty SharedSecret, enabling attackers to bypass authentication controls.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, focused exploit PoC for CVE-2019-20933 against InfluxDB. It contains two files: a long README.md explaining reconnaissance, version fingerprinting, vulnerability background, and remediation; and a single Python exploit script, exploit_influxdb.py, which is the actual entry point. The script is standalone and not part of a larger exploit framework. The exploit’s core capability is authentication bypass via a forged JWT. It constructs a standard HS256 JWT with a payload containing username='admin' and a far-future expiration timestamp, then signs it with an empty secret (b''). The token is placed in the Authorization: Bearer header and sent to the target InfluxDB /query endpoint. The script allows the operator to specify a target URL and an optional InfluxQL query; if omitted, it defaults to 'SHOW DATABASES'. Successful exploitation returns parsed JSON query results from the server. Structurally, the Python code is simple: base64url_encode() serializes JWT components, generate_jwt() creates the forged token, query_influxdb() performs the HTTP request and parses JSON output, and main() handles CLI arguments and prints results. There is no persistence, shell payload, lateral movement, or post-exploitation automation. Its purpose is direct API abuse for unauthorized database access. Fingerprintable targets and endpoints are centered on the InfluxDB HTTP API, especially /query. The README also documents /ping and /write as relevant API routes and uses 192.168.3.137:8086 as the example target. Overall, this is an operational PoC for network-based exploitation of vulnerable InfluxDB instances, enabling unauthorized execution of InfluxQL queries and exposure of database contents.
Repository is a Python JWT security testing toolkit (“claimjumper”) rather than a single exploit for one product. It provides: (1) JWT decoding and vulnerability analysis with risk scoring (claimjumper/decoder.py, analyzer.py), (2) token forging (alg=none and HS256 with a provided secret) (forger.py), (3) multi-threaded HMAC secret brute forcing for HS256/384/512 using built-in/common secrets and optional wordlists (cracker.py plus wordlists/jwt_secrets.txt; also references a Wallarm wordlist path), (4) an “advanced_attacks” module that generates multiple CVE/pattern-based attack tokens (notably CVE-2022-39227 algorithm confusion, CVE-2018-0114 key injection, CVE-2022-21449 psychic signature, CVE-2020-28042 null signature bypass, plus kid/jku/x5u/jwks spoofing and timestamp tampering), (5) a fuzzing engine with payload libraries for path traversal, SQLi, NoSQLi, command injection, SSRF, etc. (fuzzer.py), and (6) optional live HTTP replay/testing and a playbook-style scanner using `requests` (http_tester.py) that can inject tokens into requests and look for canary/response changes; it logs to jwt_attack.log. The primary entry point is the Click-based CLI (claimjumper/cli.py) exposing commands like analyze, crack, forge/forge-none, advanced-attacks, fuzz, keygen, and full-audit. A standalone local HTML UI (jwt_analyzer.html) provides basic client-side decoding/forging guidance but does not itself perform signing. Overall purpose: generate and test malicious JWT variants against vulnerable JWT verification implementations and assist in auditing JWT configurations.
This repository contains a Python exploit for CVE-2019-20933, targeting InfluxDB versions prior to 1.7.6. The exploit leverages an authentication bypass vulnerability where a JWT token with an empty shared secret is accepted, allowing unauthorized access. The main script (__main__.py) provides an interactive shell for issuing arbitrary queries to the InfluxDB instance after successful exploitation. It includes a username bruteforce feature using a local users.txt file. The exploit interacts with the InfluxDB HTTP API at the /query endpoint (default port 8086). The repository is structured with a main exploit script, a requirements file for dependencies, a README for usage instructions, and a list of common usernames for bruteforcing. The exploit is operational, providing a working shell and bruteforce capability, and is not part of a larger framework.
This repository provides a proof-of-concept (PoC) exploit for CVE-2019-20933, an authentication bypass vulnerability in InfluxDB versions prior to 1.7.6. The main exploit script, 'influx-client.py', is a Python client that generates a JWT token with an empty shared secret and uses it to send authenticated HTTP requests to the InfluxDB '/query' endpoint. This allows the attacker to execute arbitrary queries on the target database as any user, effectively bypassing authentication. The script is configurable via command-line arguments for target host, port, user, database, and query. The repository includes a README with usage instructions, a requirements.txt specifying dependencies (PyJWT and requests), and a standard MIT license. The exploit is a functional PoC and does not include weaponized or post-exploitation features.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.