← Back

CVE-2023-25827

nvd nist
Published: May 3, 2023Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Due to insufficient validation of parameters reflected in error messages by the legacy HTTP query API and the logging endpoint, it is possible to inject and execute malicious JavaScript within the browser of a targeted OpenTSDB user. This issue shares the same root cause as CVE-2018-13003, a reflected XSS vulnerability with the suggestion endpoint.

Affected (1)

Products: Opentsdb: Opentsdb
1 product
Opentsdb
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 1.0.0 to 2.4.1

References (4)

Source: disclosure@synopsys.com
Patch
Source: disclosure@synopsys.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.