Critical FluentBit Vulnerabilities Let Attackers to Cloud Environments Remotely
ID: 84c3cafc-3185-5524-a05a-9f66420498cc
STIX ID: report--84c3cafc-3185-5524-a05a-9f66420498cc
Feed Name: cybersecurityNews.com
Security researchers (Oligo Security with AWS coordination) disclosed five critical Fluent Bit vulnerabilities (including CVE-2025-12972, CVE-2025-12970, CVE-2025-12978, CVE-2025-12977, CVE-2025-12969) impacting input/output plugins that can enable path traversal and arbitrary file writes, remote code execution, authentication bypass, tag spoofing, and denial-of-service across widely deployed containerized/cloud environments; fixes were released in versions 4.1.1 and 4.0.12 and operators are advised to upgrade immediately and apply configuration hardening (explicit Path/File, static tags, non-root operation, read-only configs).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
