Записи fluentd
8 опубликованных записей вендора fluentd.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 87,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-276 Incorrect Default Permissions1
- CWE-306 Missing Authentication for Critical Function1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-409 Improper Handling of Highly Compressed Data (Data Amplification)1
- CWE-502 Deserialization of Untrusted Data1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
52В плане | CVE-2022-39379Эксплойта нет | Fluentd vulnerable to remote code execution due to insecure deserialization (in non-default configuration)fluentd · fluentd · CWE-502 | Критическая9,8 | — | 45,0 % | 2 нояб. 2022 г. |
40В плане | CVE-2017-10906Эксплойта нет | Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execufluentd · fluentd | Критическая9,8 | — | 4,6 % | 8 дек. 2017 г. |
39Наблюдать | CVE-2026-44024Proof of concept | Fluentd: Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholderfluentd · fluentd · CWE-22 | Критическая9,8 | — | 1,1 % | 8 июл. 2026 г. |
35Наблюдать | CVE-2020-21514Эксплойта нет | An issue was discovered in Fluent-ui v.1.2.2 allows attackers to gain escalated privileges and execute arbitrary code due to a default passwfluentd · fluentd · CWE-276 | Высокая8,8 | — | 0,8 % | 4 апр. 2023 г. |
31Наблюдать | CVE-2021-41186Эксплойта нет | ReDoS vulnerability in parser_apache2fluentd · fluentd · CWE-400 | Высокая7,5 | — | 2,2 % | 29 окт. 2021 г. |
30Наблюдать | CVE-2026-44160Эксплойта нет | Fluentd: Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`fluentd · fluentd · CWE-409 | Высокая7,5 | — | 0,6 % | 8 июл. 2026 г. |
30Наблюдать | CVE-2026-44025Эксплойта нет | Fluentd: Exposure of Sensitive Information via Monitor Agent APIfluentd · fluentd · CWE-306 | Высокая7,5 | — | 0,5 % | 8 июл. 2026 г. |
28Наблюдать | CVE-2026-44161Эксплойта нет | Fluentd: Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`fluentd · fluentd · CWE-918 | Высокая7,2 | — | 0,4 % | 8 июл. 2026 г. |
- CVE-2022-3937952В плане
Fluentd vulnerable to remote code execution due to insecure deserialization (in non-default configuration)
КритическаяCVSS 9,8Эксплойта нетEPSS 45 %fluentd · fluentd2 нояб. 2022 г.
- CVE-2017-1090640В плане
Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execu
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %fluentd · fluentd8 дек. 2017 г.
- CVE-2026-4402439Наблюдать
Fluentd: Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
КритическаяCVSS 9,8Proof of conceptEPSS 1 %fluentd · fluentd8 июл. 2026 г.
- CVE-2020-2151435Наблюдать
An issue was discovered in Fluent-ui v.1.2.2 allows attackers to gain escalated privileges and execute arbitrary code due to a default passw
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %fluentd · fluentd4 апр. 2023 г.
- CVE-2021-4118631Наблюдать
ReDoS vulnerability in parser_apache2
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %fluentd · fluentd29 окт. 2021 г.
- CVE-2026-4416030Наблюдать
Fluentd: Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %fluentd · fluentd8 июл. 2026 г.
- CVE-2026-4402530Наблюдать
Fluentd: Exposure of Sensitive Information via Monitor Agent API
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %fluentd · fluentd8 июл. 2026 г.
- CVE-2026-4416128Наблюдать
Fluentd: Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %fluentd · fluentd8 июл. 2026 г.