Intel

AIKIDO-2024-10425

fluent.fluent-bit is vulnerable to Improper Authentication

Improper Authentication Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Nov 6, 2024

88

High Risk

This Affects:

c++fluent.fluent-bit
3.0.0 - 3.1.9
Fixed in 3.1.10
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to improper authentication in the Forward plugin. The issue arises because the check that is in place for shared_key_digest_len does not adequately prevent an attacker from tampering with the shared_key_digest. This vulnerability could allow unauthorized users to bypass authentication mechanisms and gain access to protected resources.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

fluent.fluent-bit is vulnerable to Improper Authentication in versions 3.0.0 - 3.1.9.

How to fix this

Upgrade the fluent.fluent-bit library to the patch version.