Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9chv-3w6c-jq9w

Опубликовано: 03 мая 2023
Источник: github
Github: Прошло ревью
CVSS3: 8.2

Описание

Cross Site Scripting in OpenTSDB

Due to insufficient validation of parameters reflected in error messages by the legacy HTTP query API and the logging endpoint, it is possible to inject and execute malicious JavaScript within the browser of a targeted OpenTSDB user. This issue shares the same root cause as CVE-2018-13003, a reflected XSS vulnerability with the suggestion endpoint.

Пакеты

Наименование

net.opentsdb:opentsdb

maven
Затронутые версииВерсия исправления

<= 2.4.1

Отсутствует

EPSS

Процентиль: 45%
0.00226
Низкий

8.2 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8.2
nvd
почти 3 года назад

Due to insufficient validation of parameters reflected in error messages by the legacy HTTP query API and the logging endpoint, it is possible to inject and execute malicious JavaScript within the browser of a targeted OpenTSDB user. This issue shares the same root cause as CVE-2018-13003, a reflected XSS vulnerability with the suggestion endpoint.

EPSS

Процентиль: 45%
0.00226
Низкий

8.2 High

CVSS3

Дефекты

CWE-79