PT-2023-18548 · Netdata+4 · Netdata+4

Ralphm

·

Published

2023-01-14

·

Updated

2025-02-03

·

CVE-2023-22497

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Netdata agent versions prior to 1.37 Netdata agent versions prior to 1.36.0-409 (nightly)
Description The issue affects Netdata Agents that expose their services to non-trusted users, particularly when the streaming feature is enabled, allowing a parent Netdata Agent to handle functions for its children. An attacker can exploit this by using a valid MACHINE GUID as an API key. This can lead to unauthorized access and potential data manipulation. The estimated number of potentially affected devices is not specified.
Recommendations For Netdata agent versions prior to 1.37, update to version 1.37 or later. For Netdata agent versions prior to 1.36.0-409 (nightly), update to version 1.36.0-409 (nightly) or later. As a temporary workaround, consider disabling the streaming feature by default or limiting access to the port on the recipient Agent to trusted child connections.

Exploit

Fix

Exposure of Resource to Wrong Sphere

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1106
ALT-PU-2023-1223
CVE-2023-22497
GHSA-JX85-39CW-66F2
OESA-2024-1050
OESA-2024-1051
OESA-2024-1052
USN-7250-1

Affected Products

Alt Linux
Debian
Linuxmint
Netdata
Ubuntu