CVE-2018-18836: Code Injection
Published Jun 18, 2019
·Updated
An issue was discovered in Netdata 1.10.0. JSON injection exists via the api/v1/data tqx parameter because of webclientapirequestv1data in web/api/webapiv1.c.
Affected Software
2 affected componentsFixes available
debian/netdata
1.29.3-41.37.1-21.47.5-1
My-netdata Netdata=1.10.0
Remediation
Event History
Jun 18, 2019
CVE Published
via MITRE·03:13 PM
Data Sourced
via MITRE·03:13 PM
Description
Feb 7, 2025
Data Sourced
via Ubuntu·11:26 AM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·11:27 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18836?
CVE-2018-18836 is classified as a high severity vulnerability due to potential JSON injection risks.
2
How do I fix CVE-2018-18836?
To mitigate CVE-2018-18836, ensure that you update Netdata to a version beyond 1.10.0 where the vulnerability has been patched.
3
What specific versions of Netdata are affected by CVE-2018-18836?
CVE-2018-18836 specifically affects Netdata version 1.10.0.
4
What type of vulnerability is CVE-2018-18836?
CVE-2018-18836 is a JSON injection vulnerability that can be exploited through the api/v1/data tqx parameter in Netdata.
5
Is CVE-2018-18836 being actively exploited?
There are no specific reports of CVE-2018-18836 being actively exploited, but vulnerabilities of this nature can pose significant risks if not addressed.