CVE-2018-18837: Medium severity netdata vulnerability
Published Jun 18, 2019
·Updated
An issue was discovered in Netdata 1.10.0. HTTP Header Injection exists via the api/v1/data filename parameter because of webclientapirequestv1data in web/api/webapiv1.c.
Affected Software
1 affected component
My-netdata Netdata=1.10.0
Remediation
Event History
Jun 18, 2019
CVE Published
via MITRE·03:11 PM
Data Sourced
via MITRE·03:11 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18837?
CVE-2018-18837 has a moderate severity as it allows HTTP Header Injection vulnerabilities.
2
How do I fix CVE-2018-18837?
To fix CVE-2018-18837, upgrade Netdata to a version later than 1.10.0 where the vulnerability has been addressed.
3
What versions of Netdata are affected by CVE-2018-18837?
Netdata version 1.10.0 is the only version affected by CVE-2018-18837.
4
What type of attack can CVE-2018-18837 facilitate?
CVE-2018-18837 can facilitate attacks involving HTTP Header Injection which may lead to security issues.
5
Is CVE-2018-18837 exploitable remotely?
Yes, CVE-2018-18837 is exploitable remotely as it affects the HTTP API of Netdata.