A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter. The yrange value is written to a gnuplot file in the /tmp directory. This file is then executed via the mygnuplot.sh shell script. (tsd/GraphHandler.java attempted to prevent command injections by blocking backticks but this is insufficient.)
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T17:02:08.232Z

Reserved: 2020-12-16T00:00:00

Link: CVE-2020-35476

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-12-16T08:15:13.560

Modified: 2024-11-21T05:27:22.250

Link: CVE-2020-35476

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.