Description
An issue was discovered in OpenTSDB 2.3.0. Many parameters to the /q URI can execute commands, including o, key, style, and yrange and y2range and their JSON input.
Remediation
References
https://github.com/OpenTSDB/opentsdb/issues/1239
Related Vulnerabilities
CVE-2019-19771 Vulnerability in npm package wallet-address-validtaor
CVE-2020-2321 Vulnerability in maven package org.jenkins-ci.plugins:shelve-project-plugin
CVE-2019-20330 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2022-38900 Vulnerability in npm package decode-uri-component