Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
GHSA-44hj-4m45-frj3
No affected components available
Fluentd allows dynamically constructing file paths using the ${tag} placeholder.
It was discovered that validation for this placeholder was insufficient.
If a Fluentd instance is configured to receive logs from untrusted sources and uses the ${tag} placeholder in file configurations (such as the path parameter in the out_file plugin), an attacker can inject path traversal characters (e.g., ../).
When combined with certain formatting options, this vulnerability allows an attacker to write arbitrary files or overwrite existing files on the system with attacker-controlled content, bypassing intended directory restrictions.
Impact
This vulnerability allows for Arbitrary File Write, which can be directly escalated to full Remote Code Execution (RCE). An attacker could achieve RCE by overwriting critical system files, injecting executable plugins, or modifying configuration files. The impact is Critical as it can lead to full system compromise without any authentication, depending on the Fluentd configuration and the privileges of the Fluentd process.
Patches
v1.19.3
Workarounds
If an immediate upgrade is not possible, users are strongly advised to apply the following mitigations:
- Restrict Network Access
- Ensure that Fluentd input ports (such as
in_forwardon default port24224) are deployed within a closed, trusted network. Use firewall rules (e.g., iptables, AWS Security Groups) to block access from untrusted networks or instances.
- Ensure that Fluentd input ports (such as
- Run Fluentd as a non-root user
- Dropping privileges prevents Fluentd from writing to sensitive system directories (e.g.,
/etc/), significantly mitigating the risk of system-wide RCE.
- Dropping privileges prevents Fluentd from writing to sensitive system directories (e.g.,
- Revise configurations
- Do not use the
${tag}placeholder in thepathparameter of output plugins (likeout_file) if the tag originates from an untrusted source.
- Do not use the
- Filter incoming tags
- Strictly validate and filter incoming tags at the input layer (e.g., using
fluent-plugin-rewrite-tag-filter) to drop any tags containing.or/characters.
- Strictly validate and filter incoming tags at the input layer (e.g., using
The vulnerability can be exploited over the network without needing physical access. It is easy for an attacker to exploit this vulnerability. An attacker does not need any special privileges or access rights. No user interaction is needed for the attacker to exploit this vulnerability. The impact is confined to the system where the vulnerability exists. There is a high impact on the confidentiality of the information. There is a high impact on the integrity of the data. There is a high impact on the availability of the system.
Active exploitation in the wild has been confirmed. Immediate patching or mitigation is required.
The exploit probability is very low. The vulnerability is unlikely to be exploited in the next 30 days.
We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.
Browse More
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard