QID 981828
QID 981828: Java (maven) Security Update for net.opentsdb:opentsdb (GHSA-hv53-q76c-7f8c)
A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter. The yrange value is written to a gnuplot file in the /tmp directory. This file is then executed via the mygnuplot.sh shell script. (tsd/GraphHandler.java attempted to prevent command injections by blocking backticks but this is insufficient.)
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-hv53-q76c-7f8c for updates pertaining to this vulnerability.
Vendor References
- GHSA-hv53-q76c-7f8c -
github.com/advisories/GHSA-hv53-q76c-7f8c
CVEs related to QID 981828
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hv53-q76c-7f8c | net.opentsdb:opentsdb |
|