Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

nvd логотип

CVE-2025-12972

9 месяцев назад

Fluent Bit out_file plugin does not properly sanitize tag values when deriving output file names. When the File option is omitted, the plugin uses untrusted tag input to construct file paths. This allows attackers with network access to craft tags containing path traversal sequences that cause Fluent Bit to write files outside the intended output directory.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-mjmc-4hm9-g39m

9 месяцев назад

Fluent Bit out_file plugin does not properly sanitize tag values when deriving output file names. When the File option is omitted, the plugin uses untrusted tag input to construct file paths. This allows attackers with network access to craft tags containing path traversal sequences that cause Fluent Bit to write files outside the intended output directory.

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2025-15408

9 месяцев назад

Уязвимость плагина out_file инструмента для сбора и обработки логов Fluent Bit, позволяющая нарушителю записать произвольный файл за пределами целевой директории

CVSS3: 5.3
EPSS: Низкий
redos логотип

ROS-20260319-73-0009

5 месяцев назад

Уязвимость fluent-bit

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-12972

Fluent Bit out_file plugin does not properly sanitize tag values when deriving output file names. When the File option is omitted, the plugin uses untrusted tag input to construct file paths. This allows attackers with network access to craft tags containing path traversal sequences that cause Fluent Bit to write files outside the intended output directory.

CVSS3: 5.3
1%
Низкий
9 месяцев назад
github логотип
GHSA-mjmc-4hm9-g39m

Fluent Bit out_file plugin does not properly sanitize tag values when deriving output file names. When the File option is omitted, the plugin uses untrusted tag input to construct file paths. This allows attackers with network access to craft tags containing path traversal sequences that cause Fluent Bit to write files outside the intended output directory.

CVSS3: 5.3
1%
Низкий
9 месяцев назад
fstec логотип
BDU:2025-15408

Уязвимость плагина out_file инструмента для сбора и обработки логов Fluent Bit, позволяющая нарушителю записать произвольный файл за пределами целевой директории

CVSS3: 5.3
1%
Низкий
9 месяцев назад
redos логотип
ROS-20260319-73-0009

Уязвимость fluent-bit

CVSS3: 5.3
1%
Низкий
5 месяцев назад

Уязвимостей на страницу