CVE-2023-36812
OpenTSDB is a open source, distributed, scalable Time Series Database (TSDB). OpenTSDB is vulnerable to Remote Code Execution vulnerability by writing user-controlled input to Gnuplot configuration file and running Gnuplot with the generated configuration. This issue has been patched in commit `07c4641471c` and further refined in commit `fa88d3e4b`. These patches are available in the `2.4.2` release. Users are advised to upgrade. User unable to upgrade may disable Gunuplot via the config option`tsd.core.enable_ui = true` and remove the shell files `mygnuplot.bat` and `mygnuplot.sh`.
- Affected products
- Opentsdb
- Opentsdb
- < 2.4.2
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 16.5% (97th percentile)
- Weakness
- CWE-74
- NVD status
- Modified
- Published
- 2023-06-30
CVE-2023-36812 at NVD
5 known exploits for CVE-2023-36812
Proof-of-concept code and exploit modules indexed by Sploitus