Bug ID 1139094
Summary VUL-0: CVE-2018-18836: netdata: JSON injection
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.1
Hardware Other
URL https://smash.suse.de/issue/235364/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Other
Assignee bnc-team-screening@forge.provo.novell.com
Reporter abergmann@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2018-18836

An issue was discovered in Netdata 1.10.0. JSON injection exists via the
api/v1/data tqx parameter because of web_client_api_request_v1_data in
web/api/web_api_v1.c.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-18836
http://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-18836.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18836
https://github.com/netdata/netdata/blob/798c141c49ee85bddc8f48f25d2cb593ec96da07/web/api/web_api_v1.c#L403
https://github.com/netdata/netdata/commit/92327c9ec211bd1616315abcb255861b130b97ca
https://github.com/netdata/netdata/pull/4521
https://www.red4sec.com/cve/netdata_json_injection.txt
https://github.com/netdata/netdata/blob/798c141c49ee85bddc8f48f25d2cb593ec96da07/web/api/web_api_v1.c#L388


You are receiving this mail because: