USN-7250-1: Netdata vulnerabilities

Published Feb 3, 2025
·
Updated

It was discovered that Netdata incorrectly handled parsing JSON input, which could lead to a JSON injection. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-18836) It was discovered that Netdata incorrectly handled parsing HTTP headers, which could lead to a HTTP header injection. An attacker could possibly use this issue to cause a denial of service or leak sensitive information. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-18837) It was discovered that Netdata incorrectly handled parsing URLs, which could lead to a log injection. An attacker could possibly use this issue to consume system resources, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-18838) It was discovered Netdata improperly authenticated API keys. An attacker could possibly use this issue to leak sensitive information or execute arbitrary code. This issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2023-22497) It was discovered Fluent Bit, vendored in Netdata, incorrectly handled parsing HTTP payloads. An attacker could possibly use this issue to disrupt logging. This issue only affected Ubuntu 24.10. (CVE-2024-23722) It was discovered that WebAssembly Micro Runtime, vendored in Netdata, incorrectly handled memory. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 24.10. (CVE-2024-34250, CVE-2024-34251)

Affected Software

18 affected componentsFixes available
All of the following
ubuntu/netdata-core<1.44.3-2ubuntu0.1
1.44.3-2ubuntu0.1
Ubuntu Ubuntu=24.10
All of the following
ubuntu/netdata-plugins-bash<1.44.3-2ubuntu0.1
1.44.3-2ubuntu0.1
Ubuntu Ubuntu=24.10
All of the following
ubuntu/netdata-web<1.44.3-2ubuntu0.1
1.44.3-2ubuntu0.1
Ubuntu Ubuntu=24.10
All of the following
ubuntu/netdata-core<1.33.1-1ubuntu1+esm1
1.33.1-1ubuntu1+esm1
Ubuntu Ubuntu=22.04
All of the following
ubuntu/netdata-plugins-bash<1.33.1-1ubuntu1+esm1
1.33.1-1ubuntu1+esm1
Ubuntu Ubuntu=22.04
All of the following
ubuntu/netdata-web<1.33.1-1ubuntu1+esm1
1.33.1-1ubuntu1+esm1
Ubuntu Ubuntu=22.04
All of the following
ubuntu/netdata-core<1.19.0-3ubuntu1+esm1
1.19.0-3ubuntu1+esm1
Ubuntu Ubuntu=20.04
All of the following
ubuntu/netdata<1.9.0+dfsg-1ubuntu0.1~esm1
1.9.0+dfsg-1ubuntu0.1~esm1
Ubuntu Ubuntu=18.04
All of the following
ubuntu/netdata-data<1.9.0+dfsg-1ubuntu0.1~esm1
1.9.0+dfsg-1ubuntu0.1~esm1
Ubuntu Ubuntu=18.04

Event History

Feb 3, 2025
Advisory Published
via Ubuntu·12:00 AM

Frequently Asked Questions

1

What are the potential impacts of USN-7250-1?

The vulnerability in USN-7250-1 may allow an attacker to perform JSON injection and potentially execute arbitrary code.

2

Who is affected by USN-7250-1?

Only users running Netdata on Ubuntu 18.04 LTS are affected by the vulnerability described in USN-7250-1.

3

How can I mitigate the risks associated with USN-7250-1?

To mitigate the risks of USN-7250-1, users should update their Netdata installation to the patched version specified in the advisory.

4

What is the recommended version to upgrade to for USN-7250-1?

The recommended version to upgrade to for resolving the issue in USN-7250-1 is 1.44.3-2ubuntu0.1 or the latest available version.

5

Is the vulnerability described in USN-7250-1 exploitable remotely?

Yes, the vulnerability in USN-7250-1 may be exploited remotely if the affected Netdata instance is exposed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203