CVE-2023-25827

Source
https://cve.org/CVERecord?id=CVE-2023-25827
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-25827.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-25827
Aliases
Published
2023-05-03T18:36:14.126Z
Modified
2026-08-12T03:51:43.367209985Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N CVSS Calculator
Summary
Cross-site Scripting in OpenTSDB
Details

Due to insufficient validation of parameters reflected in error messages by the legacy HTTP query API and the logging endpoint, it is possible to inject and execute malicious JavaScript within the browser of a targeted OpenTSDB user. This issue shares the same root cause as CVE-2018-13003, a reflected XSS vulnerability with the suggestion endpoint.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/25xxx/CVE-2023-25827.json",
    "cna_assigner": "SNPS"
}
References

Affected packages

Git / github.com/opentsdb/opentsdb

Affected ranges

Type
GIT
Repo
https://github.com/opentsdb/opentsdb
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:opentsdb:opentsdb:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.4.1"
        },
        {
            "introduced": "1.0.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ]
}

Affected versions

2.*
2.1.1
v1.*
v1.0.0
v1.1.0
v2.*
v2.0.1
v2.1.0
v2.1.2
v2.1.3
v2.1.4
v2.2.0
v2.2.1
v2.2.2
v2.3.0
v2.3.1
v2.3.2
v2.4.0
v2.4.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-25827.json"