Bug ID 1139095
Summary VUL-0: CVE-2018-18837: netdata: HTTP Header Injection
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.1
Hardware Other
URL https://smash.suse.de/issue/235365/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Other
Assignee bnc-team-screening@forge.provo.novell.com
Reporter abergmann@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2018-18837

An issue was discovered in Netdata 1.10.0. HTTP Header Injection exists via the
api/v1/data filename parameter because of web_client_api_request_v1_data in
web/api/web_api_v1.c.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-18837
http://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-18837.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18837
https://www.red4sec.com/cve/netdata_header_injection.txt
https://github.com/netdata/netdata/pull/4521
https://github.com/netdata/netdata/commit/92327c9ec211bd1616315abcb255861b130b97ca
https://github.com/netdata/netdata/blob/798c141c49ee85bddc8f48f25d2cb593ec96da07/web/api/web_api_v1.c#L367-L370


You are receiving this mail because: