CVE-2025-12969: Medium severity Fluent Fluent Bit vulnerability
CVE-2025-12969
Other sources
Fluent Bit inforward input plugin does not properly enforce the security.users authentication mechanism under certain configuration conditions. This allows remote attackers with network access to the Fluent Bit instance exposing the forward input to send unauthenticated data. By bypassing authentication controls, attackers can inject forged log records, flood alerting systems, or manipulate routing decisions, compromising the authenticity and integrity of ingested logs.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12969?
CVE-2025-12969 is considered to have a high severity due to its potential for unauthorized data access.
How do I fix CVE-2025-12969?
To fix CVE-2025-12969, ensure that the security.users authentication mechanism is properly enforced in the configuration of Fluent Bit.
Who is affected by CVE-2025-12969?
CVE-2025-12969 affects any users of the Fluent Bit in_forward input plugin that have not correctly configured user authentication.
What type of attack is possible with CVE-2025-12969?
CVE-2025-12969 allows remote attackers to send unauthenticated data to a vulnerable Fluent Bit instance.
Is there a workaround for CVE-2025-12969?
A potential workaround for CVE-2025-12969 is to limit network access to the Fluent Bit instance until the proper configuration is applied.