Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jhcc-gw3q-f4pc

Опубликовано: 20 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 8.8

Описание

Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype pollution that enables remote code execution. 

To remediate this issue, users should upgrade to OpenSearch Dashboards 3.8 or later.

Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype pollution that enables remote code execution. 

To remediate this issue, users should upgrade to OpenSearch Dashboards 3.8 or later.

EPSS

Процентиль: 49%
0.00664
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-1321

Связанные уязвимости

CVSS3: 8.8
nvd
около 1 месяца назад

Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype pollution that enables remote code execution.  To remediate this issue, users should upgrade to OpenSearch Dashboards 3.8 or later.

EPSS

Процентиль: 49%
0.00664
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-1321