Description
An issue was discovered in OpenTSDB 2.3.0. Many parameters to the /q URI can execute commands, including o, key, style, and yrange and y2range and their JSON input.
Remediation
References
https://github.com/OpenTSDB/opentsdb/issues/1239
Related Vulnerabilities
CVE-2023-1436 Vulnerability in maven package org.codehaus.jettison:jettison
CVE-2022-42496 Vulnerability in npm package nadesiko3
CVE-2022-25354 Vulnerability in npm package set-in
CVE-2023-49371 Vulnerability in maven package com.ruoyi:ruoyi
CVE-2018-11775 Vulnerability in maven package org.apache.activemq:activemq-client