summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorGyorgy Sarvari <skandigraun@gmail.com>2026-03-04 12:39:56 +0100
committerGyorgy Sarvari <skandigraun@gmail.com>2026-03-07 21:05:37 +0100
commit4642efcb9cffe4a06b5a464d5dab6108ac33bf28 (patch)
treefaf7000471e67ab80ac949f59cf1918c98838652
parentbd5d3494e4c38697741670a72416a3f240e2a297 (diff)
downloadmeta-openembedded-4642efcb9cffe4a06b5a464d5dab6108ac33bf28.tar.gz
netdata: patch CVE-2023-22497
Details: https://nvd.nist.gov/vuln/detail/CVE-2023-22497 This patch was selected based on its description, and based on the associated PR. The description matches the issue described in the NVD advisory, and the PR credits the same reported that is also credited with the CVE ID (in the release notes of the application). Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
-rw-r--r--meta-webserver/recipes-webadmin/netdata/netdata/CVE-2023-22497.patch120
-rw-r--r--meta-webserver/recipes-webadmin/netdata/netdata_1.34.1.bb4
2 files changed, 123 insertions, 1 deletions
diff --git a/meta-webserver/recipes-webadmin/netdata/netdata/CVE-2023-22497.patch b/meta-webserver/recipes-webadmin/netdata/netdata/CVE-2023-22497.patch
new file mode 100644
index 0000000000..5aa2fde328
--- /dev/null
+++ b/meta-webserver/recipes-webadmin/netdata/netdata/CVE-2023-22497.patch
@@ -0,0 +1,120 @@
1From 1aa77696d0853ab515eddea8ee7a7d16d3813571 Mon Sep 17 00:00:00 2001
2From: Costa Tsaousis <costa@netdata.cloud>
3Date: Tue, 29 Nov 2022 17:28:17 +0200
4Subject: [PATCH] Strict control of streaming API keys and MACHINE GUIDs in
5 stream.conf (#14063)
6
7do not allow machine guids to be used as API keys
8
9CVE: CVE-2023-22497
10Upstream-Status: Backport [https://github.com/netdata/netdata/commit/811028aea2f146cc0ac2bc403f7d692add400d63]
11Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
12---
13 streaming/rrdpush.c | 30 ++++++++++++++++++++++++------
14 streaming/stream.conf | 10 ++++++++++
15 2 files changed, 34 insertions(+), 6 deletions(-)
16
17diff --git a/streaming/rrdpush.c b/streaming/rrdpush.c
18index 8829d1e..0a0d9fc 100644
19--- a/streaming/rrdpush.c
20+++ b/streaming/rrdpush.c
21@@ -594,21 +594,30 @@ int rrdpush_receiver_thread_spawn(struct web_client *w, char *url) {
22
23 if(regenerate_guid(key, buf) == -1) {
24 rrdhost_system_info_free(system_info);
25- log_stream_connection(w->client_ip, w->client_port, (key && *key)?key:"-", (machine_guid && *machine_guid)?machine_guid:"-", (hostname && *hostname)?hostname:"-", "ACCESS DENIED - INVALID KEY");
26+ log_stream_connection(w->client_ip, w->client_port, key, machine_guid, hostname, "ACCESS DENIED - INVALID KEY");
27 error("STREAM [receive from [%s]:%s]: API key '%s' is not valid GUID (use the command uuidgen to generate one). Forbidding access.", w->client_ip, w->client_port, key);
28 return rrdpush_receiver_permission_denied(w);
29 }
30
31 if(regenerate_guid(machine_guid, buf) == -1) {
32 rrdhost_system_info_free(system_info);
33- log_stream_connection(w->client_ip, w->client_port, (key && *key)?key:"-", (machine_guid && *machine_guid)?machine_guid:"-", (hostname && *hostname)?hostname:"-", "ACCESS DENIED - INVALID MACHINE GUID");
34+ log_stream_connection(w->client_ip, w->client_port, key, machine_guid, hostname, "ACCESS DENIED - INVALID MACHINE GUID");
35 error("STREAM [receive from [%s]:%s]: machine GUID '%s' is not GUID. Forbidding access.", w->client_ip, w->client_port, machine_guid);
36 return rrdpush_receiver_permission_denied(w);
37 }
38
39+ const char *api_key_type = appconfig_get(&stream_config, key, "type", "api");
40+ if(!api_key_type || !*api_key_type) api_key_type = "unknown";
41+ if(strcmp(api_key_type, "api") != 0) {
42+ rrdhost_system_info_free(system_info);
43+ log_stream_connection(w->client_ip, w->client_port, key, machine_guid, hostname, "ACCESS DENIED - API KEY GIVEN IS NOT API KEY");
44+ error("STREAM [receive from [%s]:%s]: API key '%s' is a %s GUID. Forbidding access.", w->client_ip, w->client_port, key, api_key_type);
45+ return rrdpush_receiver_permission_denied(w);
46+ }
47+
48 if(!appconfig_get_boolean(&stream_config, key, "enabled", 0)) {
49 rrdhost_system_info_free(system_info);
50- log_stream_connection(w->client_ip, w->client_port, (key && *key)?key:"-", (machine_guid && *machine_guid)?machine_guid:"-", (hostname && *hostname)?hostname:"-", "ACCESS DENIED - KEY NOT ENABLED");
51+ log_stream_connection(w->client_ip, w->client_port, key, machine_guid, hostname, "ACCESS DENIED - KEY NOT ENABLED");
52 error("STREAM [receive from [%s]:%s]: API key '%s' is not allowed. Forbidding access.", w->client_ip, w->client_port, key);
53 return rrdpush_receiver_permission_denied(w);
54 }
55@@ -619,7 +628,7 @@ int rrdpush_receiver_thread_spawn(struct web_client *w, char *url) {
56 if(!simple_pattern_matches(key_allow_from, w->client_ip)) {
57 simple_pattern_free(key_allow_from);
58 rrdhost_system_info_free(system_info);
59- log_stream_connection(w->client_ip, w->client_port, (key && *key)?key:"-", (machine_guid && *machine_guid)?machine_guid:"-", (hostname && *hostname) ? hostname : "-", "ACCESS DENIED - KEY NOT ALLOWED FROM THIS IP");
60+ log_stream_connection(w->client_ip, w->client_port, key, machine_guid, hostname, "ACCESS DENIED - KEY NOT ALLOWED FROM THIS IP");
61 error("STREAM [receive from [%s]:%s]: API key '%s' is not permitted from this IP. Forbidding access.", w->client_ip, w->client_port, key);
62 return rrdpush_receiver_permission_denied(w);
63 }
64@@ -627,9 +636,18 @@ int rrdpush_receiver_thread_spawn(struct web_client *w, char *url) {
65 }
66 }
67
68+ const char *machine_guid_type = appconfig_get(&stream_config, machine_guid, "type", "machine");
69+ if(!machine_guid_type || !*machine_guid_type) machine_guid_type = "unknown";
70+ if(strcmp(machine_guid_type, "machine") != 0) {
71+ rrdhost_system_info_free(system_info);
72+ log_stream_connection(w->client_ip, w->client_port, key, machine_guid, hostname, "ACCESS DENIED - MACHINE GUID GIVEN IS NOT A MACHINE GUID");
73+ error("STREAM [receive from [%s]:%s]: machine GUID '%s' is a %s GUID. Forbidding access.", w->client_ip, w->client_port, machine_guid, machine_guid_type);
74+ return rrdpush_receiver_permission_denied(w);
75+ }
76+
77 if(!appconfig_get_boolean(&stream_config, machine_guid, "enabled", 1)) {
78 rrdhost_system_info_free(system_info);
79- log_stream_connection(w->client_ip, w->client_port, (key && *key)?key:"-", (machine_guid && *machine_guid)?machine_guid:"-", (hostname && *hostname)?hostname:"-", "ACCESS DENIED - MACHINE GUID NOT ENABLED");
80+ log_stream_connection(w->client_ip, w->client_port, key, machine_guid, hostname, "ACCESS DENIED - MACHINE GUID NOT ENABLED");
81 error("STREAM [receive from [%s]:%s]: machine GUID '%s' is not allowed. Forbidding access.", w->client_ip, w->client_port, machine_guid);
82 return rrdpush_receiver_permission_denied(w);
83 }
84@@ -640,7 +658,7 @@ int rrdpush_receiver_thread_spawn(struct web_client *w, char *url) {
85 if(!simple_pattern_matches(machine_allow_from, w->client_ip)) {
86 simple_pattern_free(machine_allow_from);
87 rrdhost_system_info_free(system_info);
88- log_stream_connection(w->client_ip, w->client_port, (key && *key)?key:"-", (machine_guid && *machine_guid)?machine_guid:"-", (hostname && *hostname) ? hostname : "-", "ACCESS DENIED - MACHINE GUID NOT ALLOWED FROM THIS IP");
89+ log_stream_connection(w->client_ip, w->client_port, key, machine_guid, hostname, "ACCESS DENIED - MACHINE GUID NOT ALLOWED FROM THIS IP");
90 error("STREAM [receive from [%s]:%s]: Machine GUID '%s' is not permitted from this IP. Forbidding access.", w->client_ip, w->client_port, machine_guid);
91 return rrdpush_receiver_permission_denied(w);
92 }
93diff --git a/streaming/stream.conf b/streaming/stream.conf
94index e65e76f..7229ade 100644
95--- a/streaming/stream.conf
96+++ b/streaming/stream.conf
97@@ -115,6 +115,11 @@
98 [API_KEY]
99 # Default settings for this API key
100
101+ # This GUID is to be used as an API key from remote agents connecting
102+ # to this machine. Failure to match such a key, denies access.
103+ # YOU MUST SET THIS FIELD ON ALL API KEYS.
104+ type = api
105+
106 # You can disable the API key, by setting this to: no
107 # The default (for unknown API keys) is: no
108 enabled = no
109@@ -184,6 +189,11 @@
110 # you can give settings for each sending host here.
111
112 [MACHINE_GUID]
113+ # This GUID is to be used as a MACHINE GUID from remote agents connecting
114+ # to this machine, not an API key.
115+ # YOU MUST SET THIS FIELD ON ALL MACHINE GUIDs.
116+ type = machine
117+
118 # enable this host: yes | no
119 # When disabled, the parent will not receive metrics for this host.
120 # THIS IS NOT A SECURITY MECHANISM - AN ATTACKER CAN SET ANY OTHER GUID.
diff --git a/meta-webserver/recipes-webadmin/netdata/netdata_1.34.1.bb b/meta-webserver/recipes-webadmin/netdata/netdata_1.34.1.bb
index 516fde6281..4d57b84b07 100644
--- a/meta-webserver/recipes-webadmin/netdata/netdata_1.34.1.bb
+++ b/meta-webserver/recipes-webadmin/netdata/netdata_1.34.1.bb
@@ -7,7 +7,9 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=fc9b848046ef54b5eaee6071947abd24"
7 7
8DEPENDS += "libuv util-linux zlib" 8DEPENDS += "libuv util-linux zlib"
9 9
10SRC_URI = "https://github.com/${BPN}/${BPN}/releases/download/v${PV}/${BPN}-v${PV}.tar.gz" 10SRC_URI = "https://github.com/${BPN}/${BPN}/releases/download/v${PV}/${BPN}-v${PV}.tar.gz \
11 file://CVE-2023-22497.patch \
12 "
11SRC_URI[sha256sum] = "8ea0786df0e952209c14efeb02e25339a0769aa3edc029e12816b8ead24a82d7" 13SRC_URI[sha256sum] = "8ea0786df0e952209c14efeb02e25339a0769aa3edc029e12816b8ead24a82d7"
12 14
13# default netdata.conf for netdata configuration 15# default netdata.conf for netdata configuration