cbcvebase.
CVE-2017-10906
published 2017-12-08

CVE-2017-10906: Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execute arbitrary…

PriorityP260critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
4.58%
90.6th percentile
Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execute arbitrary commands on the device via unspecified vectors.

Affected

16 ranges
VendorProductVersion rangeFixed in
cloud_native_computing_foundationfluentd
fluentdfluentd
fluentdfluentd
fluentdfluentd
fluentdfluentd
fluentdfluentd
fluentdfluentd
fluentdfluentd
fluentdfluentd
fluentdfluentd
fluentdfluentd
fluentdfluentd
fluentdfluentd
fluentdfluentd>= 0.12.29 < 0.12.410.12.41
linuxlinux_kernel>= 0 < 4.4.0-166.1954.4.0-166.195
redhatopenstack

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerable code path is in filter_parser.rb:filter_stream — monitor for escape sequence injection in log output processed by this function
  • Exploitation requires filter_parser to be enabled in fluentd.conf — audit fluentd configurations for filter_parser usage as a detection/triage step
  • Exploitation requires Fluentd running in non-daemon mode — detect fluentd processes running in foreground/non-daemon mode as a risk indicator
  • Attack vector is a specially crafted log entry containing escape sequences — inspect ingested log content for terminal escape sequences (e.g. ESC [ sequences) as anomaly indicators
  • ·All three preconditions must be simultaneously present for exploitation: (1) filter_parser enabled, (2) non-daemon mode or unsanitised syslog, (3) vulnerable terminal interacting with fluentd output — absence of any one prevents exploitation
  • ·rsyslog sanitises escape sequences and is therefore not a viable attack path via syslog — deployments using rsyslog as the syslog server are not exposed through that vector

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv7.0HIGH
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.