Description
An issue was discovered in OpenTSDB 2.3.0. Many parameters to the /q URI can execute commands, including o, key, style, and yrange and y2range and their JSON input.
Remediation
References
https://github.com/OpenTSDB/opentsdb/issues/1239
Related Vulnerabilities
CVE-2022-36077 Vulnerability in npm package electron
CVE-2019-25075 Vulnerability in maven package io.gravitee.management:gravitee-management-api-service
CVE-2016-10531 Vulnerability in maven package org.webjars.bower:marked
CVE-2021-23568 Vulnerability in npm package extend2
CVE-2021-40525 Vulnerability in maven package org.apache.james:james-server