Skip to content

CVE-2023-25826 #2288

@nneufelder

Description

@nneufelder

Hello openTSDB,

Questions for you, has CVE-2023-25826 been addressed or resolved? I can't seem to find any evidence in your repo to suggest the vulnerability was addressed. Additionally, there are several, recent active exploits publicly available for this vulnerability.

Currently the only open CVE advisory listed in the Security tab is CVE-2023-36812. CVE-2023-36812 seems to describe CVE-2023-25826, and both CVEs link to the exact same patch. Are they the same vulnerability?

exploitation tools for CVE-2023-25826:
https://packetstormsecurity.com/files/174570/OpenTSDB-2.4.1-Unauthenticated-Command-Injection.html
https://github.com/ErikWynter/opentsdb_key_cmd_injection

Thank you!,
Nathan

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions