PT-2018-11505 · Opentsdb · Opentsdb

Mikeluengo

·

Published

2018-06-29

·

Updated

2022-05-13

·

CVE-2018-12972

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenTSDB version 2.3.0
Description An issue was discovered where many parameters to the "/q" URI can execute commands. The vulnerable parameters include o, key, style, and yrange and y2range along with their JSON input.
Recommendations For OpenTSDB version 2.3.0, consider restricting access to the "/q" URI or limiting the execution of commands through the vulnerable parameters o, key, style, yrange, and y2range to minimize the risk of exploitation. Avoid using these parameters with JSON input until the issue is resolved.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-12972
GHSA-CX2V-JRJC-G54W

Affected Products

Opentsdb