PT-2025-47922 · Unknown+2 · Fluent-Bit+2
Published
2025-11-23
·
Updated
2026-03-19
·
CVE-2025-12972
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Fluent Bit versions prior to 4.1.1
Description
The out file plugin in Fluent Bit does not properly sanitize tag values when creating output file names. If the
File option is not specified, the plugin utilizes tag input, which is considered untrusted, to construct file paths. This allows attackers with network access to manipulate tags with path traversal sequences, potentially causing Fluent Bit to write files to locations outside the designated output directory. The issue enables unauthorized file writing.Recommendations
Upgrade to Fluent Bit version 4.1.1 or later.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fluent-Bit
Red Os
Out File Plugin