CVE Vulnerabilities

CVE-2017-10906

Published: Dec 08, 2017 | Modified: Aug 04, 2021
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execute arbitrary commands on the device via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Fluentd Fluentd 0.12.29 0.12.29
Fluentd Fluentd 0.12.30 0.12.30
Fluentd Fluentd 0.12.31 0.12.31
Fluentd Fluentd 0.12.32 0.12.32
Fluentd Fluentd 0.12.33 0.12.33
Fluentd Fluentd 0.12.34 0.12.34
Fluentd Fluentd 0.12.35 0.12.35
Fluentd Fluentd 0.12.36 0.12.36
Fluentd Fluentd 0.12.37 0.12.37
Fluentd Fluentd 0.12.38 0.12.38
Fluentd Fluentd 0.12.39 0.12.39
Fluentd Fluentd 0.12.40 0.12.40

References