Description
Fluent Bit in_forward input plugin does not properly enforce the security.users authentication mechanism under certain configuration conditions. This allows remote attackers with network access to the Fluent Bit instance exposing the forward input to send unauthenticated data. By bypassing authentication controls, attackers can inject forged log records, flood alerting systems, or manipulate routing decisions, compromising the authenticity and integrity of ingested logs.
INFO
Published Date :
2025-11-24T14:41:05.630Z
Last Modified :
2026-01-07T15:36:49.065Z
Source :
certcc
AFFECTED PRODUCTS
The following products are affected by CVE-2025-12969 vulnerability.
| Vendors | Products |
|---|---|
| Treasuredata |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-12969.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact