Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-12978

Опубликовано: 24 нояб. 2025
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a flaw in the tag_key validation logic that fails to enforce exact key-length matching. This allows crafted inputs where a tag prefix is incorrectly treated as a full match. A remote attacker with authenticated or exposed access to these input endpoints can exploit this behavior to manipulate tags and redirect records to unintended destinations. This compromises the authenticity of ingested logs and can allow injection of forged data, alert flooding and routing manipulation.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:treasuredata:fluent_bit:4.1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 36%
0.00153
Низкий

5.4 Medium

CVSS3

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 5.4
github
3 месяца назад

Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a flaw in the tag_key validation logic that fails to enforce exact key-length matching. This allows crafted inputs where a tag prefix is incorrectly treated as a full match. A remote attacker with authenticated or exposed access to these input endpoints can exploit this behavior to manipulate tags and redirect records to unintended destinations. This compromises the authenticity of ingested logs and can allow injection of forged data, alert flooding and routing manipulation.

CVSS3: 5.4
fstec
5 месяцев назад

Уязвимость механизма валидации tag_key инструмента для сбора и обработки логов Fluent Bit, позволяющая нарушителю оказать влияние на целостность и доступность защищаемой информации

EPSS

Процентиль: 36%
0.00153
Низкий

5.4 Medium

CVSS3

Дефекты

NVD-CWE-noinfo