CRITICAL

CVE-2023-36812

CVSS v3

9.8

CRITICAL

EPSS Score

84.3%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

OpenTSDB is a open source, distributed, scalable Time Series Database (TSDB). OpenTSDB is vulnerable to Remote Code Execution vulnerability by writing user-controlled input to Gnuplot configuration file and running Gnuplot with the generated configuration. This issue has been patched in commit `07c4641471c` and further refined in commit `fa88d3e4b`. These patches are available in the `2.4.2` release. Users are advised to upgrade. User unable to upgrade may disable Gunuplot via the config option`tsd.core.enable_ui = true` and remove the shell files `mygnuplot.bat` and `mygnuplot.sh`.

Technical details

Published
6/30/2023

Frequently asked questions

What is CVE-2023-36812?

OpenTSDB is a open source, distributed, scalable Time Series Database (TSDB). OpenTSDB is vulnerable to Remote Code Execution vulnerability by writing user-controlled input to Gnuplot configuration file and running Gnuplot with the generated configuration. This issue has been patched in commit `07c4641471c` and further refined in commit `fa88d3e4b`. These patches are available in the `2.4.2` release. Users are advised to upgrade. User unable to upgrade may disable Gunuplot via the config option`tsd.core.enable_ui = true` and remove the shell files `mygnuplot.bat` and `mygnuplot.sh`.

Is CVE-2023-36812 actively exploited?

Active exploitation of CVE-2023-36812 has not been confirmed. The EPSS score is 84.3%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2023-36812?

CVE-2023-36812 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2023-36812 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.