Back to search
CVE-2017-10906
Published: Dec 8, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execute arbitrary commands on the device via unspecified vectors.
| Vendor | Product | Versions |
|---|---|---|
Cloud Native Computing Foundation (CNCF) | Fluentd | affected 0.12.29 through 0.12.40 |
References
RHSA-2018:2225
vendor-advisory
x_refsource_REDHAT
https://jvn.jp/en/vu/JVNVU95124098/index.html
x_refsource_MISC
https://github.com/fluent/fluentd/blob/v0.12/CHANGELOG.md#bug-fixes
x_refsource_CONFIRM
https://github.com/fluent/fluentd/pull/1733
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now