Loading
An issue was discovered in OpenTSDB 2.3.0. Many parameters to the /q URI can execute commands, including o, key, style, and yrange and y2range and their JSON input.
Use CWE-78, Opentsdb vendor hub and Opentsdb product page to widen CVE-2018-12972 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-36812, CVE-2023-25826 and CVE-2020-35476 for nearby disclosures in the same product family.