Record summary

CVE-2023-25826 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS commands into multiple parameters and execute malicious code on the OpenTSDB host system. This exploit exists due to an incomplete fix that was made when this vulnerability was previously disclosed as CVE-2020-35476. Regex validation that was implemented to restrict allowed input to the query API does not work as intended, allowing crafted commands to bypass validation.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 29, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListThrough 2.4.1affected
GitHub AdvisoryThrough 2.4.1affected

Proofs of concept

2

Catalogued exploits

MetasploitOpenTSDB 2.4.1 unauthenticated command injectionMetasploit exploitby Daniel Abeles +2 moreNot analyzed1 file

Ruby · linked to 2 vulnerabilities

Metasploit

PoC details

Repository PoCs

GitHubErikWynter/opentsdb_key_cmd_injectionRepository PoCby ErikWynterStars: 7Not analyzed7 files

241.9 KiB · linked to 2 vulnerabilities

GitHub

PoC details

References

5