CVE-2017-10906
Fluentd Escape Sequence Injection Vulnerability
9.8
CRITICAL
CVSS 3.1
EPSS 4.6%
Description
Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execute arbitrary commands on the device via unspecified vectors.
How to fix CVE-2017-10906
To remediate CVE-2017-10906, upgrade the affected package to a fixed version below.
- RubyGems/fluentd—upgrade to 0.12.41 or later
Is CVE-2017-10906 being exploited?
Low — EPSS is 4.6%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 0.12.29, < 0.12.41
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |