A high-severity CVE (CVSS 7.5) has been disclosed in Fluentd affecting the `in_http` and `in_forward` plugins. Both plugins support gzip-compressed data but fail to enforce size limits on decompressed output. An attacker on an untrusted network can send a crafted gzip decompression bomb that expands to an excessive size in memory, bypassing configured payload size limits and causing an Out-of-Memory kill of the Fluentd process. This disrupts all log collection and forwarding on the affected node. The vulnerability is patched in Fluentd version 1.19.3 and later.

1m read timeFrom rubysec.com
Post cover image
Table of contents
Impact
509 Impressions