GHSA-hwhf-64mh-r662

    Dashboard / Vulnerabilities / GHSA-hwhf-64mh-r662

    GHSA-hwhf-64mh-r662

    Published: 1 Nov 2021Last Modified: 8 Jul 2026

    Summary: ReDoS vulnerability in parser_apache2

    Details: ### Impact parser_apache2 plugin in Fluentd v0.14.14 to v1.14.1 suffers from a regular expression denial of service (ReDoS) vulnerability. A broken apache log with a certain pattern of string can spend too much time in a regular expression, resulting in the potential for a DoS attack. ### Patches v1.14.2 ### Workarounds Either of the following: * Don't use parser_apache2 for parsing logs which cannot guarantee generated by Apache. * Put patched version of parser_apache2.rb into /etc/fluent/plugin directory (or any other directories specified by the environment variable `FLUENT_PLUGIN` or `--plugin` option of fluentd). ### References * [CVE-2021-41186](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41186) * [GHSA-hwhf-64mh-r662](https://github.com/fluent/fluentd/security/advisories/GHSA-hwhf-64mh-r662) * [GHSL-2021-102](https://securitylab.github.com/advisories/GHSL-2021-102-fluent-fluentd/) * https://github.com/fluent/fluentd/blob/master/CHANGELOG.md#v1142

    Affected packages

    Package

    Name: fluentd

    Purl: pkg:gem/fluentd

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0.14.14
    Fixed -1.14.2

    Affected versions

    0.14.14
    0.14.15
    0.14.16
    0.14.17
    0.14.18
    0.14.19
    0.14.20
    0.14.20.rc1
    0.14.21
    0.14.22
    0.14.22.rc1
    0.14.22.rc2
    0.14.23
    0.14.23.rc1
    0.14.24
    0.14.25

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-hwhf-64mh-r662 | CVE-DB