Impact
A flaw in the symbolic link handling of the Pack Git import feature in Cribl Stream allows a remote authenticated attacker who has Pack import and pipeline preview permissions to execute arbitrary code with the privileges of the Cribl server process. This is a classic path traversal style issue (CWE‑61) that can lead to full system compromise, data tampering, and service disruption if the attacker succeeds.
Affected Systems
The vulnerability affects Cribl Stream deployments operating on any version earlier than 4.18.2. Users of versions 4.18.1 and previous are exposed; upgrading to 4.18.2 or later removes the flaw.
Risk and Exploitability
With a CVSS score of 8.7, the vulnerability is considered high severity. The EPSS score is < 1%, indicating a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. The flaw requires remote authentication and specific Pack import and pipeline preview permissions, but once those prerequisites are satisfied an attacker could leverage the vulnerability immediately.
OpenCVE Enrichment