CVE-2018-18839: Infoleak
Published Jun 18, 2019
·Updated
DISPUTED An issue was discovered in Netdata 1.10.0. Full Path Disclosure (FPD) exists via api/v1/alarms. NOTE: the vendor says "is intentional."
Affected Software
1 affected component
My-netdata Netdata=1.10.0
Remediation
Event History
Jun 18, 2019
CVE Published
via MITRE·03:06 PM
Data Sourced
via MITRE·03:06 PM
Description
Disputed
04:15 PM
Frequently Asked Questions
1
What is the severity of CVE-2018-18839?
The severity of CVE-2018-18839 is currently disputed, as the vendor claims that the Full Path Disclosure is intentional.
2
How do I fix CVE-2018-18839?
There is no fix for CVE-2018-18839 since the vendor states that the Full Path Disclosure behavior is intentional.
3
What is Full Path Disclosure in the context of CVE-2018-18839?
Full Path Disclosure in CVE-2018-18839 refers to the exposure of the file paths on the server via the Netdata API.
4
Which version of Netdata is affected by CVE-2018-18839?
CVE-2018-18839 affects Netdata version 1.10.0.
5
Is CVE-2018-18839 considered a critical vulnerability?
CVE-2018-18839 is not considered critical, but it can expose sensitive information about the server.