CVE-2020-28169: High severity fluentd vulnerability
Published Dec 24, 2020
·Updated
The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory is writable by a user account, but a file in bin is executed as NT AUTHORITY\SYSTEM.
Affected Software
3 affected components
Td-agent-builder Project Td-agent-builder Fluentd<2020-12-18
Microsoft Windows
Debian Debian Linux=10.0
Remediation
Event History
Dec 24, 2020
CVE Published
via MITRE·02:36 PM
Data Sourced
via MITRE·02:36 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-28169?
CVE-2020-28169 has a high severity rating due to the potential for privilege escalation if exploited.
2
How do I fix CVE-2020-28169?
To fix CVE-2020-28169, you should update the td-agent-builder plugin to version 2020-12-18 or later.
3
What causes CVE-2020-28169?
CVE-2020-28169 is caused by inappropriate file permissions in the bin directory, allowing a user to execute files as NT AUTHORITY\SYSTEM.
4
Which versions are affected by CVE-2020-28169?
CVE-2020-28169 affects versions of the td-agent-builder plugin prior to 2020-12-18.
5
Can CVE-2020-28169 be exploited on all operating systems?
CVE-2020-28169 is primarily an issue on Windows systems where Fluentd is installed and the td-agent-builder plugin is used.