Netdata is an open source observability tool. From 2.0.0 until 2.11.0, Netdata registers /api/v3/settings in src/web/api/v3/web_api_v3.c with HTTP_ACL_NOCHECK and HTTP_ACCESS_ANONYMOUS_DATA, causing unauthenticated PUT requests handled by src/web/api/v3/api_v3
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
未找到公开 POC。
登录以生成 AI POC| CVE-2026-83603 | 8.4 HIGH | Netdata: Local Root via ndsudo Arbitrary socket_path → fail2ban-client Pickle RCE |
| CVE-2026-83598 | 7.8 HIGH | Netdata: Local Privilege Escalation in Netdata Agent Windows installer via PowerShell Prof |
| CVE-2026-83599 | 7.5 HIGH | Netdata: WebSocket Decompression Bomb |
| CVE-2026-83597 | 7.0 HIGH | Netdata: Local Privilege Escalation in Netdata Windows Agent installer via MSI Repair Exec |
| CVE-2026-83601 | 6.5 MEDIUM | Netdata: Streaming protocol dimension slot has no upper-bound guard, allowing integer over |
| CVE-2026-83600 | 6.5 MEDIUM | Netdata: Streaming protocol chart slot guard off-by-one allows ~16 GiB allocation request, |
暂无评论