BIT-fluent-bit-2025-12969

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/fluent-bit/BIT-fluent-bit-2025-12969.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-fluent-bit-2025-12969
Aliases
Published
2025-12-01T20:38:24.940Z
Modified
2025-12-01T21:42:55.111835Z
Summary
CVE-2025-12969
Details

Fluent Bit in_forward input plugin does not properly enforce the security.users authentication mechanism under certain configuration conditions. This allows remote attackers with network access to the Fluent Bit instance exposing the forward input to send unauthenticated data. By bypassing authentication controls, attackers can inject forged log records, flood alerting systems, or manipulate routing decisions, compromising the authenticity and integrity of ingested logs.

Database specific
{
    "cpes": [
        "cpe:2.3:a:treasuredata:fluent_bit:*:*:*:*:*:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / fluent-bit

Package

Name
fluent-bit
Purl
pkg:bitnami/fluent-bit

Severity

  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
4.1.0
Fixed
4.1.1

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/fluent-bit/BIT-fluent-bit-2025-12969.json"