Fluent Bit in_forward input plugin does not properly enforce the security.users authentication mechanism under certain configuration conditions. This allows remote attackers with network access to the Fluent Bit instance exposing the forward input to send unauthenticated data. By bypassing authentication controls, attackers can inject forged log records, flood alerting systems, or manipulate routing decisions, compromising the authenticity and integrity of ingested logs.
References
Configurations
History
28 Nov 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
28 Nov 2025, 15:23
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:treasuredata:fluent_bit:4.1.0:*:*:*:*:*:*:* | |
| First Time |
Treasuredata fluent Bit
Treasuredata |
|
| References | () https://fluentbit.io/announcements/v4.1.0/ - Release Notes | |
| CWE | CWE-306 |
24 Nov 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
24 Nov 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-24 15:15
Updated : 2025-11-28 18:15
NVD link : CVE-2025-12969
Mitre link : CVE-2025-12969
CVE.ORG link : CVE-2025-12969
JSON object : View
Products Affected
treasuredata
- fluent_bit
CWE
CWE-306
Missing Authentication for Critical Function
