Description
An issue was discovered in OpenTSDB 2.3.0. There is XSS in parameter 'type' to the /suggest URI.
Remediation
References
https://github.com/OpenTSDB/opentsdb/issues/1241
Related Vulnerabilities
CVE-2021-37305 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base
CVE-2020-10688 Vulnerability in maven package org.jboss.resteasy:resteasy-core
CVE-2021-33561 Vulnerability in maven package com.shopizer:shopizer
CVE-2019-20922 Vulnerability in npm package handlebars
CVE-2016-10624 Vulnerability in npm package selenium-chromedriver