PT-2022-24940 · Fluentd · Fluentd
Ashie
·
Published
2022-11-02
·
Updated
2025-09-19
·
CVE-2022-39379
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Fluentd versions 1.13.2 through 1.15.2
Description
A remote code execution vulnerability in non-default configurations of Fluentd allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads. This issue affects Fluentd setups where the environment variable
FLUENT OJ OPTION MODE is explicitly set to object. The option FLUENT OJ OPTION MODE was introduced in Fluentd version 1.13.2, and earlier versions are not affected.Recommendations
For Fluentd versions 1.13.2 through 1.15.2, update to version 1.15.3 to resolve the issue.
As a temporary workaround for affected versions, do not use
FLUENT OJ OPTION MODE=object.Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fluentd