Description
An issue was discovered in OpenTSDB 2.3.0. Many parameters to the /q URI can execute commands, including o, key, style, and yrange and y2range and their JSON input.
Remediation
References
https://github.com/OpenTSDB/opentsdb/issues/1239
Related Vulnerabilities
CVE-2016-10557 Vulnerability in npm package appium-chromedriver
CVE-2017-12634 Vulnerability in maven package org.apache.camel:camel-castor
CVE-2020-7647 Vulnerability in maven package org.jooby:jooby
CVE-2020-7597 Vulnerability in npm package codecov
CVE-2019-20921 Vulnerability in maven package org.webjars.bowergithub.thdoan:bootstrap-select