github.com
https://github.com/OpenTSDB/opentsdb CVE-2023-25827
HIGH
Cross-site Scripting in OpenTSDB
Record summary
CVE-2023-25827 has a selected CVSS score of 8.2 (high).
Description
Due to insufficient validation of parameters reflected in error messages by the legacy HTTP query API and the logging endpoint, it is possible to inject and execute malicious JavaScript within the browser of a targeted OpenTSDB user. This issue shares the same root cause as CVE-2018-13003, a reflected XSS vulnerability with the suggestion endpoint.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 29, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
OpenTSDBBrowse OpenTSDB / OpenTSDBDefault status: unaffected | CVE List | Through 2.4.1 | affected |
net.opentsdb:opentsdbBrowse Maven / net.opentsdb:opentsdb | GitHub Advisory | Through 2.4.1 | affected |
References
4github.com
https://github.com/OpenTSDB/opentsdb/pull/2274 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-25827 synopsys.com
https://www.synopsys.com/blogs/software-security/opentsdb