BIT-fluentd-2021-41186

    Dashboard / Vulnerabilities / BIT-fluentd-2021-41186

    BIT-fluentd-2021-41186

    Published: 6 Mar 2024Last Modified: 8 Sept 2026

    Summary: ReDoS vulnerability in parser_apache2

    Details: Fluentd collects events from various data sources and writes them to files to help unify logging infrastructure. The parser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of service (ReDoS) vulnerability. A broken apache log with a certain pattern of string can spend too much time in a regular expression, resulting in the potential for a DoS attack. This issue is patched in version 1.14.2 There are two workarounds available. Either don't use parser_apache2 for parsing logs (which cannot guarantee generated by Apache), or put patched version of parser_apache2.rb into /etc/fluent/plugin directory (or any other directories specified by the environment variable `FLUENT_PLUGIN` or `--plugin` option of fluentd).

    Affected packages

    Package

    Name: fluentd

    Purl: pkg:bitnami/fluentd

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0.14.14
    Fixed -1.14.2

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    BIT-fluentd-2021-41186 | CVE-DB