PT-2023-18547 · Netdata+2 · Netdata+2

Published

2023-01-14

·

Updated

2024-01-12

·

CVE-2023-22496

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Netdata agent versions prior to 1.37 (stable) and 1.36.0-409 (nightly)
Description An issue exists where an attacker can execute arbitrary commands on a targeted Netdata agent by establishing a streaming connection and providing a specially crafted registry hostname as part of the health data. This is possible because the health alarm execute function calls spawn enq cmd with unsanitized arguments, including registry hostname. The commands are executed as the user running the Netdata Agent, usually named netdata. This may allow an attacker to escalate privileges by exploiting other vulnerabilities in the system.
Recommendations For versions prior to 1.37 (stable) and 1.36.0-409 (nightly), update to the fixed version to resolve the issue. As a temporary workaround, consider disabling the streaming feature if it has been previously enabled. Restrict access to the port on the recipient Agent to trusted child connections to minimize the risk of exploitation.

Exploit

Fix

Command Injection

RCE

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1106
ALT-PU-2023-1223
CVE-2023-22496
GHSA-XG38-3VMW-2978
OESA-2024-1050
OESA-2024-1051
OESA-2024-1052

Affected Products

Alt Linux
Debian
Netdata