Command injection in OpenTSDB - CVE-2018-12972
Published: August 22, 2018 / Updated: August 23, 2018
OpenTSDB
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary commands on the target system.
The vulnerability exists due to improper setting of security restrictions on o, key, style, yrange, and y2range parameters and their JSON input to the /q URI A remote unauthenticated attacker can send a specially crafted request that submits malicious input and execute arbitrary commands.