fixed vulnerabilities identified by red4sec.com (#4521)
Costa Tsaousis committed
Oct 30, 2018 at 02:35 UTC
92327c9ec211bd1616315abcb255861b130b97ca
2 files changed
+20
-1
libnetdata/url/url.c
+3
-1
@@ -60,7 +60,9 @@ char *url_decode_r(char *to, char *url, size_t size) {
60
while(*s && d < e) {
61
if(unlikely(*s == '%')) {
62
if(likely(s[1] && s[2])) {
63
- *d++ = from_hex(s[1]) << 4 | from_hex(s[2]);
63
+ char t = from_hex(s[1]) << 4 | from_hex(s[2]);
64
+ // avoid HTTP header injection
65
+ *d++ = (char)((isprint(t))? t : ' ');
66
s += 2;
67
}
68
}
web/api/web_api_v1.c
+17
@@ -233,6 +233,15 @@ inline int web_client_api_request_v1_chart(RRDHOST *host, struct web_client *w,
233
return web_client_api_request_single_chart(host, w, url, rrd_stats_api_v1_chart);
234
}
235
236
+void fix_google_param(char *s) {
237
+ if(unlikely(!s)) return;
238
+
239
+ for( ; *s ;s++) {
240
+ if(!isalnum(*s) && *s != '.' && *s != '_' && *s != '-')
241
+ *s = '_';
242
+ }
243
+}
244
+
245
// returns the HTTP code
246
inline int web_client_api_request_v1_data(RRDHOST *host, struct web_client *w, char *url) {
247
debug(D_WEB_CLIENT, "%llu: API v1 data with URL '%s'", w->id, url);
@@ -332,6 +341,14 @@ inline int web_client_api_request_v1_data(RRDHOST *host, struct web_client *w, c
341
}
342
}
343
344
+ // validate the google parameters given
345
+ fix_google_param(google_out);
346
+ fix_google_param(google_sig);
347
+ fix_google_param(google_reqId);
348
+ fix_google_param(google_version);
349
+ fix_google_param(responseHandler);
350
+ fix_google_param(outFileName);
351
+
352
if(!chart || !*chart) {
353
buffer_sprintf(w->response.data, "No chart id is given at the request.");
354
goto cleanup;