CRITICAL9.8
GHSA-5jrp-w8fr-mrww
Fluentd Escape Sequence Injection Vulnerability
Quick fix
GHSA-5jrp-w8fr-mrww — fluentd: upgrade to the fixed version with the command below.
bundle update fluentdDetails
Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execute arbitrary commands on the device via unspecified vectors.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2017-10906[ADVISORY]
- https://github.com/fluent/fluentd/pull/1733[WEB]
- https://access.redhat.com/errata/RHSA-2018:2225[WEB]
- https://github.com/fluent/fluentd[PACKAGE]
- https://github.com/fluent/fluentd/blob/v0.12/CHANGELOG.md#bug-fixes[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/fluentd/CVE-2017-10906.yml[WEB]
- https://jvn.jp/en/vu/JVNVU95124098/index.html[WEB]