Netdata is vulnerable to improper authentication
CVE-2023-22497
What is CVE-2023-22497?
This vulnerability in Netdata, an open-source solution for real-time infrastructure monitoring, arises from the way MACHINE GUIDs are handled within the streaming feature. When a Netdata Agent is configured in streaming mode, it acts as a parent for child agents, potentially exposing sensitive data if not properly secured. An attacker with access to a parent agent can exploit a valid MACHINE GUID as an unauthorized API key, compromising the security of all child agents. Users are advised to disable streaming by default, limit access to trusted connections, and upgrade to patched versions to mitigate risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
netdata < 1.36.0-409 < 1.36.0-409
netdata < 1.37 < 1.37
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
