PT-2023-20332 · Opentsdb · Opentsdb

Jamie Harris

·

Publicado

2023-05-03

·

Atualizado

2023-05-10

·

CVE-2023-25827

CVSS v3.1

8.2

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenTSDB (affected versions not specified)
Description The issue is caused by insufficient validation of parameters reflected in error messages by the legacy HTTP query API and the logging endpoint. This allows an attacker to inject and execute malicious JavaScript within the browser of a targeted OpenTSDB user. The issue is related to a reflected XSS vulnerability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-25827
GHSA-9CHV-3W6C-JQ9W

Produtos afetados

Opentsdb