Untrusted Search Path Affecting netdata/netdata package, versions [1.44.0-60,1.45.0-169)[1.45.1,1.45.3)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of concept
EPSS
0.04% (11th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-NETDATANETDATA-6613089
  • published14 Apr 2024
  • disclosed12 Apr 2024
  • creditmia-0

Introduced: 12 Apr 2024

CVE-2024-32019  (opens in a new tab)
CWE-426  (opens in a new tab)

How to fix?

Upgrade netdata/netdata to version 1.45.0-169, 1.45.3 or higher.

Overview

Affected versions of this package are vulnerable to Untrusted Search Path in ndsudo.c, which runs as root and relies on the PATH variable to locate commands. An attacker can place malicious commands in an arbitrary location on the filesystem and have them run with root privileges.

References

CVSS Scores

version 3.1