Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
Unknown
Privileges Required
Unknown
Attack Vector
Unknown
0

CVE-2023-25826

Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS commands into multiple parameters and execute malicious code on the OpenTSDB host system. This exploit exists due to an incomplete fix that was made when this vulnerability was previously disclosed as CVE-2020-35476. Regex validation that was implemented to restrict allowed input to the query API does not work as intended, allowing crafted commands to bypass validation.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

General Information

Vendors

  • OpenTSDB

Products

  • OpenTSDB

Additional Info

Technical Analysis