Description

Fluent Bit in_forward input plugin does not properly enforce the security.users authentication mechanism under certain configuration conditions. This allows remote attackers with network access to the Fluent Bit instance exposing the forward input to send unauthenticated data. By bypassing authentication controls, attackers can inject forged log records, flood alerting systems, or manipulate routing decisions, compromising the authenticity and integrity of ingested logs.

INFO

Published Date :

2025-11-24T14:41:05.630Z

Last Modified :

2026-01-07T15:36:49.065Z

Source :

certcc
AFFECTED PRODUCTS

The following products are affected by CVE-2025-12969 vulnerability.

Vendors Products
Treasuredata
  • Fluent Bit

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact