CVE-2020-28169
HIGHTd-agent-builder < 2020-12-18 - Incorrect Permission Assignment
Title source: ruleDescription
The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory is writable by a user account, but a file in bin is executed as NT AUTHORITY\SYSTEM.
Exploits (2)
nomisec
WRITEUP
by zubrahzz · poc
https://github.com/zubrahzz/FluentD-TD-agent-Exploit-CVE-2020-28169
References (8)
Scores
CVSS v3
7.0
EPSS
0.0162
EPSS Percentile
81.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-732
Status
published
Products (2)
debian/debian_linux
10.0
td-agent-builder_project/td-agent-builder
< 2020-12-18
Published
Dec 24, 2020
Tracked Since
Feb 18, 2026