QID 981828

QID 981828: Java (maven) Security Update for net.opentsdb:opentsdb (GHSA-hv53-q76c-7f8c)

A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter. The yrange value is written to a gnuplot file in the /tmp directory. This file is then executed via the mygnuplot.sh shell script. (tsd/GraphHandler.java attempted to prevent command injections by blocking backticks but this is insufficient.)

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to refer to GHSA-hv53-q76c-7f8c for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981828

    Software Advisories
    Advisory ID Software Component Link
    GHSA-hv53-q76c-7f8c net.opentsdb:opentsdb URL Logo github.com/advisories/GHSA-hv53-q76c-7f8c