6.9
CVSSv2

CVE-2020-28169

Published: 24/12/2020 Updated: 05/04/2022
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
CVSS v3 Base Score: 7 | Impact Score: 5.9 | Exploitability Score: 1
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The td-agent-builder plugin prior to 2020-12-18 for Fluentd allows malicious users to gain privileges because the bin directory is writable by a user account, but a file in bin is executed as NT AUTHORITY\SYSTEM.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

td-agent-builder_project td-agent-builder

debian debian linux 10.0

Vendor Advisories

Multiple vulnerabilities were discovered in Jetty, a Java servlet engine and webserver which could result in cross-site scripting, information disclosure, privilege escalation or denial of service For the stable distribution (buster), these problems have been fixed in version 9416-0+deb10u1 We recommend that you upgrade your jetty9 packages Fo ...

Exploits

Fluentd TD-agent plugin version 401 suffers from an insecure folder permission vulnerability ...

Github Repositories

Insecure Folder permission that lead to privilege escalation

FluentD-TD-agent-WindowsExploit <V401 CVE-2020-28169 Insecure Folder permission that leads to privilege escalation Download URL: td-agent-package-browserherokuappcom/4/windows