VDB
Sign up
CRITICAL9.8

GHSA-5jrp-w8fr-mrww

Fluentd Escape Sequence Injection Vulnerability

Quick fix

GHSA-5jrp-w8fr-mrww — fluentd: upgrade to the fixed version with the command below.

bundle update fluentd

Details

Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execute arbitrary commands on the device via unspecified vectors.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/fluentd
Introduced in: 0.12.29Fixed in: 0.12.41
Fixbundle update fluentd

References