OpenTSDB is a distributed time-series database designed for monitoring and metrics collection at scale, presenting a narrowly scoped but high-value attack surface centered on data ingestion and retrieval endpoints. Vulnerabilities affecting the product skew strongly toward critical severity and frequently acquire public exploit code, with the recurring exposure pattern driven by input-handling weaknesses including cross-site scripting, OS command injection, and broader injection flaws that affect web interfaces and command processing. Defenders should prioritize remediation of internet-reachable instances given the product's operational role and the severity tendency of its disclosures; live exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opentsdb over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-35476CRITICAL A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter. The yrange value is written to a gnuplot file in the /tmp dire | Dec 16, 2020 | 9.8 | 88 | NO | YES |
CVE-2023-25826CRITICAL Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS commands into multiple parameters and execute malicious code o | May 3, 2023 | 9.8 | 54 | NO | YES |
CVE-2023-36812CRITICAL OpenTSDB is a open source, distributed, scalable Time Series Database (TSDB). OpenTSDB is vulnerable to Remote Code Execution vulnerability by writing user-controlled input to Gnup | Jun 30, 2023 | 9.8 | 49 | NO | YES |
CVE-2018-12972CRITICAL An issue was discovered in OpenTSDB 2.3.0. Many parameters to the /q URI can execute commands, including o, key, style, and yrange and y2range and their JSON input. | Jun 29, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-12973MEDIUM An issue was discovered in OpenTSDB 2.3.0. There is XSS in parameter 'json' to the /q URI. | Jun 29, 2018 | 6.1 | 22 | NO | NO |
CVE-2023-25827MEDIUM
Due to insufficient validation of parameters reflected in error messages by the legacy HTTP query API and the logging endpoint, it is possible to inject and execute malicious Java | May 3, 2023 | 6.1 | 21 | NO | NO |
CVE-2018-13003MEDIUM An issue was discovered in OpenTSDB 2.3.0. There is XSS in parameter 'type' to the /suggest URI. | Jun 29, 2018 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opentsdb.
Media articles that mention a CVE ID that affects a product developed by Opentsdb — matched by CVE ID, not by vendor name.