CVE-2022-39379
LOWFluentd 1.13.2-1.15.2 - Unauthenticated Remote Code Execution via JSON Payload Deserialization
Title source: llmDescription
Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. A remote code execution (RCE) vulnerability in non-default configurations of Fluentd allows unauthenticated attackers to execute arbitrary code via specially crafted JSON payloads. Fluentd setups are only affected if the environment variable `FLUENT_OJ_OPTION_MODE` is explicitly set to `object`. Please note: The option FLUENT_OJ_OPTION_MODE was introduced in Fluentd version 1.13.2. Earlier versions of Fluentd are not affected by this vulnerability. This issue was patched in version 1.15.3. As a workaround do not use `FLUENT_OJ_OPTION_MODE=object`.
References (3)
Core 3
Core References
Patch, Third Party Advisory
https://github.com/fluent/fluentd/commit/48e5b85dab1b6d4c273090d538fc11b3f2fd8135
Third Party Advisory
https://github.com/fluent/fluentd/security/advisories/GHSA-fppq-mj76-fpj2
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MYD5QV66OLDHES6IKVYYM3Y3YID3VVCO/
Scores
CVSS v3
3.1
EPSS
0.0766
EPSS Percentile
92.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-502
Status
published
Products (3)
fedoraproject/fedora
37
fluentd/fluentd
1.13.2 - 1.15.3
rubygems/fluentd
1.13.2 - 1.15.3RubyGems
Published
Nov 02, 2022
Tracked Since
Feb 18, 2026