CVE-2022-39379
Fluentd vulnerable to remote code execution due to insecure deserialization (in non-default configuration)
Description
Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. A remote code execution (RCE) vulnerability in non-default configurations of Fluentd allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads. Fluentd setups are only affected if the environment variable `FLUENT_OJ_OPTION_MODE` is explicitly set to `object`. Please note: The option FLUENT_OJ_OPTION_MODE was introduced in Fluentd version 1.13.2. Earlier versions of Fluentd are not affected by this vulnerability. This issue was patched in version 1.15.3. As a workaround do not use `FLUENT_OJ_OPTION_MODE=object`.
How to fix CVE-2022-39379
To remediate CVE-2022-39379, upgrade the affected package to a fixed version below.
- —upgrade to 1.15.3 or later
- —upgrade to 1.15.3 or later
Is CVE-2022-39379 being exploited?
Moderate — EPSS is 44.7%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- >= 1.13.2, < 1.15.3
- >= 1.13.2, < 1.15.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | LOW3.1 | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N |