CVE-2025-12969
Last modified
CVE-2025-12969 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Fluent Bit in_forward input plugin does not properly enforce the security.users authentication mechanism under certain configuration conditions. This allows remote attackers with network access to the Fluent Bit instance exposing the forward input to send unauthenticated data. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
Fluent Bit in_forward input plugin does not properly enforce the security.users authentication mechanism under certain configuration conditions. This allows remote attackers with network access to the Fluent Bit instance exposing the forward input to send unauthenticated data. By bypassing authentication controls, attackers can inject forged log records, flood alerting systems, or manipulate routing decisions, compromising the authenticity and integrity of ingested logs.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Treasuredata | Fluent Bit | 4.1.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-12969?
How severe is CVE-2025-12969?
How do I fix CVE-2025-12969?
Are you affected by CVE-2025-12969?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
