Количество 5
Количество 5
CVE-2025-12972
Fluent Bit out_file plugin does not properly sanitize tag values when deriving output file names. When the File option is omitted, the plugin uses untrusted tag input to construct file paths. This allows attackers with network access to craft tags containing path traversal sequences that cause Fluent Bit to write files outside the intended output directory.
GHSA-mjmc-4hm9-g39m
Fluent Bit out_file plugin does not properly sanitize tag values when deriving output file names. When the File option is omitted, the plugin uses untrusted tag input to construct file paths. This allows attackers with network access to craft tags containing path traversal sequences that cause Fluent Bit to write files outside the intended output directory.
BDU:2025-15408
Уязвимость плагина out_file инструмента для сбора и обработки логов Fluent Bit, позволяющая нарушителю записать произвольный файл за пределами целевой директории
ROS-20260319-80-0008
Уязвимость fluent-bit
ROS-20260319-73-0009
Уязвимость fluent-bit
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-12972 Fluent Bit out_file plugin does not properly sanitize tag values when deriving output file names. When the File option is omitted, the plugin uses untrusted tag input to construct file paths. This allows attackers with network access to craft tags containing path traversal sequences that cause Fluent Bit to write files outside the intended output directory. | CVSS3: 5.3 | 1% Низкий | 9 месяцев назад | |
GHSA-mjmc-4hm9-g39m Fluent Bit out_file plugin does not properly sanitize tag values when deriving output file names. When the File option is omitted, the plugin uses untrusted tag input to construct file paths. This allows attackers with network access to craft tags containing path traversal sequences that cause Fluent Bit to write files outside the intended output directory. | CVSS3: 5.3 | 1% Низкий | 9 месяцев назад | |
BDU:2025-15408 Уязвимость плагина out_file инструмента для сбора и обработки логов Fluent Bit, позволяющая нарушителю записать произвольный файл за пределами целевой директории | CVSS3: 5.3 | 1% Низкий | 9 месяцев назад | |
ROS-20260319-80-0008 Уязвимость fluent-bit | CVSS3: 5.3 | 1% Низкий | 5 месяцев назад | |
ROS-20260319-73-0009 Уязвимость fluent-bit | CVSS3: 5.3 | 1% Низкий | 5 месяцев назад |
Уязвимостей на страницу