PT-2024-24358 · Netdata · Netdata
Mia-0
·
Published
2024-04-12
·
Updated
2025-12-06
·
CVE-2024-32019
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Netdata versions prior to 1.45.3
Netdata versions prior to 1.45.2-169
Description
Netdata is an open source observability tool. The
ndsudo tool shipped with affected versions of the Netdata Agent allows an attacker to run arbitrary programs with root permissions. The ndsudo tool is packaged as a root-owned executable with the SUID bit set. It only runs a restricted set of external commands, but its search paths are supplied by the PATH environment variable. This allows an attacker to control where ndsudo looks for these commands, which may be a path the attacker has write access to. This may lead to local privilege escalation. The estimated number of potentially affected devices worldwide is not explicitly stated, but Netdata's popularity, with over 68k stars on Github, means that many systems could be at risk.Recommendations
For Netdata versions prior to 1.45.3, upgrade to version 1.45.3 or later.
For Netdata versions prior to 1.45.2-169, upgrade to version 1.45.2-169 or later.
As a temporary workaround, consider restricting the
PATH environment variable to prevent an attacker from controlling where ndsudo looks for external commands.
Avoid using the ndsudo tool until the issue is resolved.Exploit
Fix
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netdata