CVE-2023-25826
CRITICAL
Remote Code Execution in OpenTSDB
Record summary
CVE-2023-25826 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS commands into multiple parameters and execute malicious code on the OpenTSDB host system. This exploit exists due to an incomplete fix that was made when this vulnerability was previously disclosed as CVE-2020-35476. Regex validation that was implemented to restrict allowed input to the query API does not work as intended, allowing crafted commands to bypass validation.
Description source: CVE List
Exploitation context
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
OpenTSDBBrowse OpenTSDB / OpenTSDBDefault status: unaffected | CVE List | Through 2.4.1 | affected |
net.opentsdb:opentsdbBrowse Maven / net.opentsdb:opentsdb | GitHub Advisory | Through 2.4.1 | affected |
Proofs of concept
2Catalogued exploits
MetasploitOpenTSDB 2.4.1 unauthenticated command injectionMetasploit exploitby Daniel Abeles +2 moreNot analyzed1 file
Repository PoCs
GitHubErikWynter/opentsdb_key_cmd_injectionRepository PoCby ErikWynterStars: 7Not analyzed7 files
References
5packetstormsecurity.com
http://packetstormsecurity.com/files/174570/OpenTSDB-2.4.1-Unauthenticated-Command-Injection.html github.com
https://github.com/OpenTSDB/opentsdb github.com
https://github.com/OpenTSDB/opentsdb/pull/2275 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-25826 synopsys.com
https://www.synopsys.com/blogs/software-security/opentsdb