3
I Use This!
Very Low Activity
Analyzed about 20 hours ago. based on code collected 1 day ago.
 

Security

Vulnerabilities per Version

Learn more about BDSAs
 
 

Major Versions

1yr
3yr
5yr
10yr
All
click and drag to zoom
 
 
Security Vulnerabilities for Version:
Severities:
Type
Identifier Related Record Severity Date Published Description Versions Affected
CVE-2023-36812 Critical Jun 30, 2023 OpenTSDB is a open source, distributed, scalable Time Series Database (TSDB). OpenTSDB is vulnerable to Remote Code Execution vulnerability by writing more...
2.4.1, 2.4.0, 2.3.2, 2.3.1, 2.3.0, 2.2.2, 2.2.1, 2.2.0, 2.1.4, 1.0.0
CVE-2023-25827 BDSA-2023-1056 Medium May 03, 2023 Due to insufficient validation of parameters reflected in error messages by the legacy HTTP query API and the logging endpoint, it is possible to inje more...
2.4.1, 2.4.0, 2.3.2, 2.3.1, 2.3.0, 2.2.2, 2.2.1, 2.2.0, 2.1.4, 1.0.0
CVE-2023-25826 BDSA-2023-1057 Critical May 03, 2023 Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS commands into multiple parameter more...
2.4.1, 2.4.0, 2.3.2, 2.3.1, 2.3.0, 2.2.2, 2.2.1, 2.2.0, 2.1.4, 1.0.0
BDSA-2020-3800 High Dec 16, 2020 OpenTSDB is vulnerable to remote code execution (RCE) due to insufficient validation of parameters passed to the legacy HTTP query API when generating more...
BDSA-2018-2270 High Jul 17, 2018 OpenTSDB is vulnerable to remote code execution (RCE) due to insufficient validation of parameters passed to the legacy HTTP query API when generating more...
BDSA-2018-2266 High Jul 17, 2018 OpenTSDB is vulnerable to reflected cross-site scripting (XSS) due to improper validation of user input supplied to the HTTP legacy query API. By trick more...
BDSA-2018-2082 High Jul 03, 2018 OpenTSDB is vulnerable to reflected cross-site scripting (XSS) due to improper validation of user input supplied to the suggestion endpoint. By trickin more...
BDSA-2016-1116 High Dec 05, 2017 OpenTSDB is vulnerable to remote code execution (RCE) due to insufficient validation of parameters passed to the legacy HTTP query API when generating more...