vendor:
Fluentd TD-agent plugin
by:
Adrian Bondocea
7.0
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: Fluentd TD-agent plugin
Affected Version From: <v4.0.1
Affected Version To: <v4.0.1
Patch Exists: YES
Related CWE: CVE-2020-28169
CPE: 2.3:a:fluentd:fluentd:4.0.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 x64
2020
Fluentd TD-agent plugin 4.0.1 – Insecure Folder Permission
The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory is writable by a user account, but a file in bin is executed as NT AUTHORITYSYSTEM.
Mitigation:
Ensure that the bin directory is not writable by any user account.