Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 28 Nov 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 28 Nov 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 28 Nov 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Treasuredata
Treasuredata fluent Bit |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:treasuredata:fluent_bit:4.1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Treasuredata
Treasuredata fluent Bit |
Mon, 24 Nov 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 24 Nov 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Fluent Bit in_forward input plugin does not properly enforce the security.users authentication mechanism under certain configuration conditions. This allows remote attackers with network access to the Fluent Bit instance exposing the forward input to send unauthenticated data. By bypassing authentication controls, attackers can inject forged log records, flood alerting systems, or manipulate routing decisions, compromising the authenticity and integrity of ingested logs. | |
| Title | CVE-2025-12969 | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2025-11-28T17:46:16.845Z
Reserved: 2025-11-10T17:53:38.234Z
Link: CVE-2025-12969
Updated: 2025-11-24T18:02:15.260Z
Status : Modified
Published: 2025-11-24T15:15:46.380
Modified: 2025-11-28T18:15:46.050
Link: CVE-2025-12969
No data.
OpenCVE Enrichment
No data.