PT-2021-23159 · Fluentd · Fluentd
Ashie
·
Published
2021-10-29
·
Updated
2026-03-13
·
CVE-2021-41186
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Fluentd versions 0.14.14 through 1.14.1
Description
The parser apache2 plugin in Fluentd suffers from a regular expression denial of service (ReDoS) vulnerability. A broken apache log with a certain pattern of string can spend too much time in a regular expression, resulting in the potential for a DoS attack.
Recommendations
For versions 0.14.14 through 1.14.1, either do not use the parser apache2 for parsing logs or put a patched version of parser apache2.rb into the /etc/fluent/plugin directory (or any other directories specified by the environment variable
FLUENT PLUGIN or the --plugin option of fluentd).
For version 1.14.2 and later, no action is required as this issue is patched.Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fluentd