PT-2019-9644 · Netdata+4 · Netdata+4

CVE-2018-18836

·

Published

2019-03-09

·

Updated

2025-02-03

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Netdata version 1.10.0
Description An issue exists in the software due to JSON injection via the "api/v1/data" endpoint, specifically through the tqx parameter. This is caused by the web client api request v1 data function in web/api/web api v1.c.
Recommendations For Netdata version 1.10.0, consider restricting access to the "api/v1/data" endpoint to minimize the risk of exploitation, and avoid using the tqx parameter until the issue is resolved.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1379
CVE-2018-18836
OPENSUSE-SU-2021:0647-1
OPENSUSE-SU-2021:0730-1
OPENSUSE-SU-2021:1603-1
OPENSUSE-SU-2021_0647-1
OPENSUSE-SU-2024:11083-1
USN-7250-1

Affected Products

Alt Linux
Linuxmint
Netdata
Suse
Ubuntu