VYPR

Bitnami package

fluentd

pkg:bitnami/fluentd

Vulnerabilities (7)

  • CVE-2026-44161HigJul 8, 2026
    affected < 1.19.3fixed 1.19.3

    Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, the Fluentd out_http output plugin allows placeholders such as ${tag} in the endpoint configuration parameter, and if a placeholder value is de

  • CVE-2026-44160HigJul 8, 2026
    affected < 1.19.3fixed 1.19.3

    Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd's in_http and in_forward plugins support gzip-compressed data but enforce limits only on compressed payloads through settings such as b

  • CVE-2026-44025HigJul 8, 2026
    affected < 1.19.3fixed 1.19.3

    Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd's Monitor Agent plugin in_monitor_agent exposes internal metrics and plugin information via a REST API, and responses from /api/plugins

  • CVE-2026-44024CriJul 8, 2026
    affected < 1.19.3fixed 1.19.3

    Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd allows dynamically constructing file paths using the ${tag} placeholder, and insufficient validation of ${tag} in file configurations s

  • CVE-2020-21514HigApr 4, 2023
    affected >= 1.8.0, < 1.8.1fixed 1.8.1

    An issue was discovered in Fluent-ui v.1.2.2 allows attackers to gain escalated privileges and execute arbitrary code due to a default password.

  • CVE-2022-39379LowNov 2, 2022
    affected >= 1.13.2, < 1.15.3fixed 1.15.3

    Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. A remote code execution (RCE) vulnerability in non-default configurations of Fluentd allows unauthenticated attackers to execute arbitrary code via specially cr

  • CVE-2021-41186MedOct 29, 2021
    affected >= 0.14.14, < 1.14.2fixed 1.14.2

    Fluentd collects events from various data sources and writes them to files to help unify logging infrastructure. The parser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of service (ReDoS) vulnerability. A broken apache log with a certain