Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Opentsdb CRITICAL 9.8
CVE-2023-36812EPSS 17%

OpenTSDB is a open source, distributed, scalable Time Series Database (TSDB). OpenTSDB is vulnerable to Remote Code Execution vulnerability by writin…

Fix: 2.4.2+
Fix from $2,300 2023-06-30
Opentsdb MEDIUM 6.1
CVE-2023-25827

Due to insufficient validation of parameters reflected in error messages by the legacy HTTP query API and the logging endpoint, it is possible to inj…

Fix: after 2.4.1
Fix from $1,600 2023-05-03
Opentsdb CRITICAL 9.8
CVE-2023-25826EPSS 36%

Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS commands into multiple paramete…

Fix: after 2.4.1
Fix from $2,300 2023-05-03
Opentsdb CRITICAL 9.8
CVE-2020-35476EPSS 85%

A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter. The yrange value is written to …

Fix: after 2.4.0
Fix from $2,300 2020-12-16
Opentsdb MEDIUM 6.1
CVE-2018-13003

An issue was discovered in OpenTSDB 2.3.0. There is XSS in parameter 'type' to the /suggest URI.

Mitigation only
Fix from $1,600 2018-06-29
Opentsdb CRITICAL 9.8
CVE-2018-12972

An issue was discovered in OpenTSDB 2.3.0. Many parameters to the /q URI can execute commands, including o, key, style, and yrange and y2range and th…

Mitigation only
Fix from $2,300 2018-06-29
Opentsdb MEDIUM 6.1
CVE-2018-12973

An issue was discovered in OpenTSDB 2.3.0. There is XSS in parameter 'json' to the /q URI.

Mitigation only
Fix from $1,600 2018-06-29