logo

Critical FluentBit Vulnerabilities Let Attackers to Cloud Environments Remotely

ID: 84c3cafc-3185-5524-a05a-9f66420498cc

STIX ID: report--84c3cafc-3185-5524-a05a-9f66420498cc

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-11-25

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Security researchers (Oligo Security with AWS coordination) disclosed five critical Fluent Bit vulnerabilities (including CVE-2025-12972, CVE-2025-12970, CVE-2025-12978, CVE-2025-12977, CVE-2025-12969) impacting input/output plugins that can enable path traversal and arbitrary file writes, remote code execution, authentication bypass, tag spoofing, and denial-of-service across widely deployed containerized/cloud environments; fixes were released in versions 4.1.1 and 4.0.12 and operators are advised to upgrade immediately and apply configuration hardening (explicit Path/File, static tags, non-root operation, read-only configs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.