An issue was discovered in Netdata 1.10.0. Full Path Disclosure (FPD) exists via api/v1/alarms. NOTE: the vendor says "is intentional.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://github.com/netdata/netdata/commit/92327c9ec211bd1616315abcb255861b130b97ca | third party advisory patch |
https://github.com/netdata/netdata/pull/4521 | third party advisory |
https://www.red4sec.com/cve/netdata_fpd.txt | third party advisory |