CVE-2024-32019: ndsudo: local privilege escalation via untrusted search path
Netdata is an open source observability tool. In affected versions the ndsudo tool shipped with affected versions of the Netdata Agent allows an attacker to run arbitrary programs with root permissions. The ndsudo tool is packaged as a root-owned executable with the SUID bit set. It only runs a restricted set of external commands, but its search paths are supplied by the PATH environment variable. This allows an attacker to control where ndsudo looks for these commands, which may be a path the attacker has write access to. This may lead to local privilege escalation. This vulnerability has been addressed in versions 1.45.3 and 1.45.2-169. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32019?
CVE-2024-32019 is classified as a high-severity vulnerability due to its potential to allow attackers to execute arbitrary commands with root privileges.
How do I fix CVE-2024-32019?
To fix CVE-2024-32019, upgrade to the latest version of the Netdata Agent that addresses this vulnerability.
What versions of the Netdata Agent are affected by CVE-2024-32019?
CVE-2024-32019 affects versions of the Netdata Agent up to 1.45.2-169 and 1.45.3.
What is the impact of CVE-2024-32019 on systems?
CVE-2024-32019 allows unauthorized users to gain root access and run arbitrary programs, posing a significant security risk to affected systems.
Is there a workaround for CVE-2024-32019 if I can't update?
If an update cannot be applied immediately, consider restricting access to the ndsudo tool or implementing additional monitoring to help mitigate potential misuse.