PT-2023-20332 · Opentsdb · Opentsdb

Jamie Harris

·

Published

2023-05-03

·

Updated

2023-05-10

·

CVE-2023-25827

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenTSDB (affected versions not specified)
Description The issue is caused by insufficient validation of parameters reflected in error messages by the legacy HTTP query API and the logging endpoint. This allows an attacker to inject and execute malicious JavaScript within the browser of a targeted OpenTSDB user. The issue is related to a reflected XSS vulnerability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-25827
GHSA-9CHV-3W6C-JQ9W

Affected Products

Opentsdb