Description
An issue was discovered in OpenTSDB 2.3.0. There is XSS in parameter 'type' to the /suggest URI.
Remediation
References
https://github.com/OpenTSDB/opentsdb/issues/1241
Related Vulnerabilities
CVE-2020-17533 Vulnerability in maven package org.apache.accumulo:accumulo-core
CVE-2016-7103 Vulnerability in maven package org.webjars.bower:jquery-ui
CVE-2019-10744 Vulnerability in npm package @sailshq/lodash
CVE-2022-46175 Vulnerability in npm package json5
CVE-2022-41881 Vulnerability in maven package io.netty:netty-codec-haproxy