CVE-2018-18838: High severity netdata vulnerability
Published Jun 18, 2019
·Updated
An issue was discovered in Netdata 1.10.0. Log Injection (or Log Forgery) exists via a %0a sequence in the url parameter to api/v1/registry.
Affected Software
2 affected componentsFixes available
debian/netdata
1.29.3-41.37.1-21.47.5-1
My-netdata Netdata=1.10.0
Remediation
Event History
Jun 18, 2019
CVE Published
via MITRE·03:10 PM
Data Sourced
via MITRE·03:10 PM
Description
Feb 7, 2025
Data Sourced
via Ubuntu·11:26 AM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·11:27 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18838?
CVE-2018-18838 is classified as a medium severity vulnerability due to its potential for log injection.
2
How do I fix CVE-2018-18838?
To fix CVE-2018-18838, upgrade Netdata to a version newer than 1.10.0 that addresses this vulnerability.
3
What type of attack does CVE-2018-18838 facilitate?
CVE-2018-18838 facilitates log injection attacks, which can lead to log forgery and potential manipulation of logs.
4
In which version of Netdata is CVE-2018-18838 present?
CVE-2018-18838 is present in version 1.10.0 of Netdata.
5
What component of Netdata is affected by CVE-2018-18838?
CVE-2018-18838 affects the API component of Netdata, specifically the registry endpoint.