REDHAT-BUG-1524783: Command Injection
Escape sequence injection vulnerability in the filterparser.rb:filterstream function of Fluentd versions 0.12.29 through 0.12.40 may allow for unescaped arbitrary command injection to log files and terminal output.
Processing a specially crafted log may allow for arbitrary command exectuion on the device collecting logs.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-10906 https://github.com/fluent/fluentd/blob/v0.12/CHANGELOG.md#bug-fixes https://github.com/fluent/fluentd/pull/1733 https://jvn.jp/en/vu/JVNVU95124098/index.html
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1524783?
The severity of REDHAT-BUG-1524783 is considered to be critical due to the potential for arbitrary command execution.
How do I fix REDHAT-BUG-1524783?
To fix REDHAT-BUG-1524783, upgrade Fluentd to a version later than 0.12.40.
What are the affected versions of Fluentd for REDHAT-BUG-1524783?
Fluentd versions 0.12.29 through 0.12.40 are affected by REDHAT-BUG-1524783.
What type of vulnerability is REDHAT-BUG-1524783?
REDHAT-BUG-1524783 is an escape sequence injection vulnerability.
What can an attacker achieve with REDHAT-BUG-1524783?
An attacker can achieve arbitrary command injection into log files and terminal output with REDHAT-BUG-1524783.