Bug ID 1129854
Summary VUL-0: CVE-2019-9834: netdata: HTML injection of malicious code into an imported snapshot
Classification openSUSE
Product openSUSE Distribution
Version Leap 42.3
Hardware Other
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee nirmoy.das@suse.com
Reporter kbabioch@suse.com
QA Contact security-team@suse.de
Found By ---
Blocker ---

The Netdata web application through 1.13.0 allows remote attackers to inject
their own malicious HTML code into an imported snapshot, aka HTML Injection.
Successful exploitation will allow attacker-supplied HTML to run in the context
of the affected browser, potentially allowing the attacker to steal
authentication credentials or to control how the site is rendered to the user.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-9834
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9834
https://www.youtube.com/watch?v=zSG93yX0B8k
https://www.exploit-db.com/exploits/46545


You are receiving this mail because: