CVE Vulnerabilities

CVE-2017-10906

Published: Dec 08, 2017 | Modified: Apr 20, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execute arbitrary commands on the device via unspecified vectors.

Affected Software

NameVendorStart VersionEnd Version
FluentdFluentd0.12.29 (including)0.12.29 (including)
FluentdFluentd0.12.30 (including)0.12.30 (including)
FluentdFluentd0.12.31 (including)0.12.31 (including)
FluentdFluentd0.12.32 (including)0.12.32 (including)
FluentdFluentd0.12.33 (including)0.12.33 (including)
FluentdFluentd0.12.34 (including)0.12.34 (including)
FluentdFluentd0.12.35 (including)0.12.35 (including)
FluentdFluentd0.12.36 (including)0.12.36 (including)
FluentdFluentd0.12.37 (including)0.12.37 (including)
FluentdFluentd0.12.38 (including)0.12.38 (including)
FluentdFluentd0.12.39 (including)0.12.39 (including)
FluentdFluentd0.12.40 (including)0.12.40 (including)
Red Hat OpenStack Platform 13.0 Operational Tools for RHEL 7RedHatfluentd-0:0.12.41-1.el7*

References