Description
An issue was discovered in OpenTSDB 2.3.0. Many parameters to the /q URI can execute commands, including o, key, style, and yrange and y2range and their JSON input.
Remediation
References
https://github.com/OpenTSDB/opentsdb/issues/1239
Related Vulnerabilities
CVE-2016-10698 Vulnerability in npm package mystem-fix
CVE-2016-10546 Vulnerability in npm package pouchdb
CVE-2018-1288 Vulnerability in maven package org.apache.kafka:kafka_2.12
CVE-2022-31367 Vulnerability in npm package strapi-plugin-content-type-builder
CVE-2022-36914 Vulnerability in maven package org.jenkins-ci.plugins:files-found-trigger