Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
•
IT Security NachrichtenDeutschlands digitaler Drahtseilakt - Universität Bonn(30.09.2026 um 03:05 Uhr)
•
IT Security Nachrichten8 Companies Delivering CVE-Free Container Images in 2026(30.09.2026 um 03:05 Uhr)
••
AI & KI NachrichtenGitHub Release: openai/codex vrust-v0.161.0-alpha.3 (30.09.2026)(30.09.2026 um 03:29 Uhr)
•••••••
IT Security NachrichtenDeutschlands digitaler Drahtseilakt - Universität Bonn(30.09.2026 um 03:05 Uhr)
•
IT Security Nachrichten8 Companies Delivering CVE-Free Container Images in 2026(30.09.2026 um 03:05 Uhr)
••
AI & KI NachrichtenGitHub Release: openai/codex vrust-v0.161.0-alpha.3 (30.09.2026)(30.09.2026 um 03:29 Uhr)
••••••
Intelligence View
⚡ tsecurity.de Intelligence

Fluent Bit vulnerabilities could enable full cloud takeover

Fluent Bit, a widely deployed log-processing tool used in containers, Kubernetes DaemonSets, and major cloud platforms, has been found vulnerable to authentication bypass, file-write, and agent takeover attacks. According to an Oligo…

0
↗ Quelle (networkworld.com)
Reagiere als Erste:r — dein Feedback zählt!








Fluent Bit, a widely deployed log-processing tool used in containers, Kubernetes DaemonSets, and major cloud platforms, has been found vulnerable to authentication bypass, file-write, and agent takeover attacks.





According to an Oligo Security analysis, disclosed in co-operation with Amazon Web Services (AWS), the tool was found vulnerable to five critical flaws that could allow full compromise of cloud infrastructure.





“Fluent Bit runs everywhere: AI labs, banks, car manufacturers, all the major cloud providers such as AWS, Google Cloud, and Microsoft Azure, and more,” Uri Katz, researcher at Oligo Security’s CTO Office, said in a blog post. “When a component this widespread and trusted fails, it doesn’t just expose individual systems; it threatens the stability of the cloud ecosystem.”





These flaws can potentially allow attackers to rewrite or delete logs to cover their tracks, inject false telemetry, reroute records into attacker-controlled destinations, or even execute arbitrary code, Katz added.





To address them, the Fluent Bit project has released patched versions v4.1.1 and v4.0.12.





Bypassing authentication to inject fake logs





The most concerning issue revealed in the disclosure is the Fluent Bit forward input plugin “in_forward,” which can be configured to appear protected but is actually wide open. Specifically, when “Security.Users” authentication is specified without a “Shared.key”, authentication is effectively not enforced, leaving a vulnerable port for attackers to connect and send arbitrary logs.





Attackers could flood monitoring systems with false or misleading events, hide alerts in the noise, or even hijack the telemetry stream entirely, Katz said. The issue is now tracked as CVE-2025-12969 and awaits a severity valuation.





Almost equally troubling are other flaws in the “tag” mechanism, which determines how the records are routed and processed. One bug (CVE-2025-12978) allows an attacker who can guess just the first character of the tag key to impersonate trusted tags and reroute logs or bypass filters. Another (CVE-2025-12977) allows unsanitized tag values (including newlines, directory-traversal strings, and control characters), which can corrupt downstream parsing, enable file-system writes, or allow further escalation.





According to the blog, AWS has secured all of its internal systems that rely on Fluentbit through the Fluentbit project and released Fluentbit version 4.1.1. AWS did not immediately respond to CSO’s request for comment.





File writes, container overflow, and full agent takeover





Oligo also disclosed a chain of remote code execution (RCE) and path traversal vulnerabilities affecting the tool. CVE-2025-12972 targets the “out_file“ output plugin. When Tag values are user-controlled, and no fixed File parameter is set, attackers can abuse the Tag value (e.g.,”../“) to cause path-traversal file writes or overwrites, ultimately letting them plant malicious files or gain RCE.





“Our research found that some of these vulnerabilities, such as CVE 2025-12972, have left cloud environments vulnerable for over 8 years,” Katz noted.





In the Docker input plugin (in-Docker), CVE-2025-12970 shows a stack buffer overflow. If an attacker names a container with an excessively long name, the buffer overflow lets them crash the agent or execute code. Oligo warned that the flaw allows attackers to seize the logging agent, hide their activity, plant backdoors, and pivot further into the system.





Fluent Bit is a Cloud Native Computing Foundation (CNCF) graduated open-source project, initially created by Eduardo Silva, who remains its most frequent contributor, now sponsored and maintained by major cloud providers.


2. Cyber Threat Intelligence & Forensik

IoC Intelligence (5 Indikatoren)
CVE-2025-12969CVE-2025-12978CVE-2025-12977CVE-2025-12972CVE-2025-12970
CTI Threat Relationship Graph6 Knoten / 5 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
Exploit & Remediation Lifecycle Timeline
CVE-2025-12970
Entdeckung & Meldung
Schwachstelle identifiziert & registriert
Sicherheits-Advisory
Offizielle Warnung & CVE-Zuweisung
Exploit / PoC
Bislang kein öffentlicher Exploit
In-the-Wild Ausnutzung
Keine Massenausnutzung gemeldet
Patch & Schutzmaßnahmen
Noch kein offizieller Patch dokumentiert
Exploit Weaponization & Public PoC Radar
ELEVATED · Index 35/100
Exploit-DB
Kein EDB-Eintrag
Interaktion
0-Click
Authentifizierung
Erforderlich

3. Compliance, SLA & Vendor Adherence

CVSS 8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Impact: 5.87 | Exploitability: 2.84
AVN
Netzwerk (Remote)
Aus der Ferne über das Internet ohne Vorbedingungen exploitbar.
ACL
Niedrig (Low)
Wiederholbar und deterministisch ohne spezielle Race Conditions ausnutzbar.
PRL
Niedrig (Standard-Benutzer)
Erfordert Anmeldedaten eines regulären Benutzers.
UIN
Keine (Zero-Click)
Autonom ohne menschliches Zutun ausführbar (Zero-Click Exploitation).
SU
Unverändert (Scope Unchanged)
Auswirkungen verbleiben isoliert in der angreifbaren Anwendungskomponente.
CH
Hoch (Totaler Abfluss)
Vollständiger Zugriff auf alle sensiblen Datenbank- und Speicherinhalte.
IH
Hoch (Volle Manipulation)
Vollständige Modifikation von Dateien, Parametern oder Ausführung von Code.
AH
Hoch (Totaler Ausfall / DoS)
Dienst oder Server wird komplett unbrauchbar (Denial of Service).
BSI-Warnung (Deutschland)CVE-2025-12969
Fluent Bit: Mehrere Schwachstellen24.11.2025
CISA-SSVC-Triage (vulnrichment)CVE-2025-12969
Exploitation: none (Keine bekannte Ausnutzung)Automatable: yes (Automatisierbar)Technical Impact: partial (Teilweise)
Quelle: CISA-ADP vulnrichment · Stand 2025-11-24T18:02:22.489781Z · CISA Coordinator
Advisory Radar

Hersteller-Sicherheitsmeldungen & Patch-Status

In herstellerseitiger Prüfung
Handlungsempfehlung für Administratoren

Hersteller-Advisory noch nicht formal hinterlegt. Regelmäßiges Re-Scanning der CTI-Quellen anberaumt.

Referenzen aus der Primärquelle („Verifiziert" nur bei Hersteller-Domäne):
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Fluent Bit vulnerabilities could enable full cloud takeover

Thematisch verwandte Begriffe: Fluent, vulnerabilities, could, enable · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-71189 | An attacker can construct a request that, if issued by another applicati…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag