An issue was discovered in Netdata 1.10.0. JSON injection exists via the api/v1/data tqx parameter because of webclientapirequestv1data in web/api/webapi_v1.c.
[
{
"source": "https://github.com/netdata/netdata/commit/92327c9ec211bd1616315abcb255861b130b97ca",
"target": {
"file": "web/api/web_api_v1.c"
},
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2018-18836-1abb3bcc",
"signature_type": "Line",
"digest": {
"line_hashes": [
"66543347973657702719146160550183012649",
"338539389829895664211686211858862033147",
"181613397865496398390060114766203357490",
"311939904960053635228447904840087471795",
"69162383861090423052578740815008696676",
"295754951258971798843125484558902277741"
],
"threshold": 0.9
}
},
{
"source": "https://github.com/netdata/netdata/commit/92327c9ec211bd1616315abcb255861b130b97ca",
"target": {
"function": "web_client_api_request_v1_data",
"file": "web/api/web_api_v1.c"
},
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2018-18836-8953f44d",
"signature_type": "Function",
"digest": {
"function_hash": "204881456466600532908895856298960794977",
"length": 4676.0
}
},
{
"source": "https://github.com/netdata/netdata/commit/92327c9ec211bd1616315abcb255861b130b97ca",
"target": {
"file": "libnetdata/url/url.c"
},
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2018-18836-a1c71538",
"signature_type": "Line",
"digest": {
"line_hashes": [
"179904335846742252483163393046264994826",
"190346668020436203569205258275860151209",
"168848541308149862787108906740940067034",
"149049622975872964869544566748975749382"
],
"threshold": 0.9
}
},
{
"source": "https://github.com/netdata/netdata/commit/92327c9ec211bd1616315abcb255861b130b97ca",
"target": {
"function": "url_decode_r",
"file": "libnetdata/url/url.c"
},
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2018-18836-f8c8e8f7",
"signature_type": "Function",
"digest": {
"function_hash": "145019406472654216900235053973844180715",
"length": 450.0
}
}
]