Cross Site Scripting in OpenTSDB
High severity
GitHub Reviewed
Published
May 3, 2023
to the GitHub Advisory Database
•
Updated Nov 10, 2023
Description
Published by the National Vulnerability Database
May 3, 2023
Published to the GitHub Advisory Database
May 3, 2023
Reviewed
May 5, 2023
Last updated
Nov 10, 2023
Due to insufficient validation of parameters reflected in error messages by the legacy HTTP query API and the logging endpoint, it is possible to inject and execute malicious JavaScript within the browser of a targeted OpenTSDB user. This issue shares the same root cause as CVE-2018-13003, a reflected XSS vulnerability with the suggestion endpoint.
References