A high-severity CVE (CVSS 7.5) has been disclosed for Fluentd, the popular log aggregation tool. The Monitor Agent plugin's REST API endpoints (/api/plugins.json and related) unintentionally expose internal instance variables of loaded plugins. If any plugin stores sensitive data like database passwords, API keys, or cloud credentials in instance variables, those secrets can be read in plain text by anyone with HTTP access to the Monitor Agent port (default: 24220). The fix is available in Fluentd v1.19.3 or later.
Table of contents
Impact288 Impressions