Fluentdに複数の脆弱性
予習
この記事のキーワード — タップで意味×4
妨害
ぼうがい
disturbance; obstruction; hindrance; jamming; interference
N1×4
引き起こす
ひきおこす
1. to cause; to induce; to bring about; to provoke 2. to pull upright; to help up (e.g. a fallen person)
N1×5
処理
しょり
processing; dealing with; treatment; disposition; disposal
×3
圧縮
あっしゅく
compression; condensation; constriction; compaction
N2×3
細工
さいく
1. work; workmanship; craftsmanship; handiwork 2. artifice; trick; device; tampering; doctoring
N1
独立行政法人情報処理推進機構(IPA)および一般社団法人JPCERT コーディネーションセンター(JPCERT/CC)は6月29日、Fluentdにおける複数の脆弱性について「Japan Vulnerability Notes(JVN)」で発表した。影響を受けるシステムは以下の通り。
Fluentd v1.19.3より前のバージョン fluent-plugin-s3 1.8.5より前のバージョン fluent-plugin-opentelemetry 0.5.3より前のバージョン
※Fluentdを同梱する下記の製品も本脆弱性の影響を受ける。 fluent-package LTS版 v6.0.3およびそれ以前 fluent-package 通常版 v6.0.0 fluent-package LTS版 v5.0.9およびそれ以前 fluent-package 通常版 v5.2.0およびそれ以前
Fluentd Projectが提供するFluentdには、下記の影響を受ける可能性がある複数の脆弱性が存在する。
・${tag} Placeholderにおけるパストラバーサル(CVE-2026-44024) →管理者権限を有するプロセスで任意のシステム領域のファイルを書き換えられる
・Monitor Agent APIにおける重要な機能に対する認証の欠如(CVE-2026-44025) →設定ファイルに含まれる機微な情報をAPI経由で読み取られる
・in_httpおよびin_forwardにおける高圧縮データの不適切な処理(CVE-2026-44160) →細工されたリクエストを送信された場合、サービス運用妨害(DoS)状態を引き起こされる
・out_httpにおけるサーバサイドリクエストフォージェリ(CVE-2026-44161) →許可されていないサーバにリクエストを転送されたり、サービス運用妨害(DoS)状態を引き起こされたりする
・in_s3における高圧縮データの不適切な処理(CVE-2026-44162) →細工されたデータを処理した場合、サービス運用妨害(DoS)状態を引き起こされる
・in_opentelemetryにおける高圧縮データの不適切な処理(CVE-2026-44163) →細工されたデータを処理した場合、サービス運用妨害(DoS)状態を引き起こされる
JVNでは、開発者が提供する情報をもとに最新バージョンにアップデートするよう呼びかけている。なお開発者は、アップデートを適用するまでの間、ワークアラウンドの適用を推奨している。
Fluentd v1.19.3より前のバージョン fluent-plugin-s3 1.8.5より前のバージョン fluent-plugin-opentelemetry 0.5.3より前のバージョン
※Fluentdを同梱する下記の製品も本脆弱性の影響を受ける。 fluent-package LTS版 v6.0.3およびそれ以前 fluent-package 通常版 v6.0.0 fluent-package LTS版 v5.0.9およびそれ以前 fluent-package 通常版 v5.2.0およびそれ以前
Fluentd Projectが提供するFluentdには、下記の影響を受ける可能性がある複数の脆弱性が存在する。
・${tag} Placeholderにおけるパストラバーサル(CVE-2026-44024) →管理者権限を有するプロセスで任意のシステム領域のファイルを書き換えられる
・Monitor Agent APIにおける重要な機能に対する認証の欠如(CVE-2026-44025) →設定ファイルに含まれる機微な情報をAPI経由で読み取られる
・in_httpおよびin_forwardにおける高圧縮データの不適切な処理(CVE-2026-44160) →細工されたリクエストを送信された場合、サービス運用妨害(DoS)状態を引き起こされる
・out_httpにおけるサーバサイドリクエストフォージェリ(CVE-2026-44161) →許可されていないサーバにリクエストを転送されたり、サービス運用妨害(DoS)状態を引き起こされたりする
・in_s3における高圧縮データの不適切な処理(CVE-2026-44162) →細工されたデータを処理した場合、サービス運用妨害(DoS)状態を引き起こされる
・in_opentelemetryにおける高圧縮データの不適切な処理(CVE-2026-44163) →細工されたデータを処理した場合、サービス運用妨害(DoS)状態を引き起こされる
JVNでは、開発者が提供する情報をもとに最新バージョンにアップデートするよう呼びかけている。なお開発者は、アップデートを適用するまでの間、ワークアラウンドの適用を推奨している。
この記事の単語 (49)
×5
及び
および
and; as well as
×5
処理
しょり
processing; dealing with; treatment; disposition; disposal
×4
運用
うんよう
1. making use of; application; practical use; effective management (e.g. of funds) 2. operation; handling; steering (esp. a boat)
×4
妨害
ぼうがい
disturbance; obstruction; hindrance; jamming; interference
×4
状態
じょうたい
state; condition; situation; appearance; circumstances
×4
引き起こす
ひきおこす
1. to cause; to induce; to bring about; to provoke 2. to pull upright; to help up (e.g. a fallen person)
×3
脆弱性
ぜいじゃくせい
vulnerability; weakness; fragility
×3
影響
えいきょう
1. influence; effect 2. to influence; to affect; to have an influence on; to impact; to have an effect on
×3
以前
いぜん
ago; since; before; previous
×3
圧縮
あっしゅく
compression; condensation; constriction; compaction
×3
不適切
ふてきせつ
unsuitable; inappropriate; improper
×3
細工
さいく
1. work; workmanship; craftsmanship; handiwork 2. artifice; trick; device; tampering; doctoring
×2
複数
ふくすう
plural; multiple; several
×2
下記
かき
the following
×2
版
はん
1. edition; version; printing; impression; implementation (e.g. software) 2. plate; block; cast
×2
提供
ていきょう
1. offer; tender; providing; supplying; making available; donating (blood, organs, etc.) 2. sponsoring (a TV program)
×2
情報
じょうほう
1. information; news; intelligence; advices 2. information; data contained in characters, signals, code, etc.
×2
開発者
かいはつしゃ
developer
×2
適用
てきよう
applying (e.g. a technology); adoption
×1
独立行政法人
どくりつぎょうせいほうじん
independent administrative corporation (institution, agency)
×1
情報処理推進機構
じょうほうしょりすいしんきこう
Information-technology Promotion Agency (organization)
×1
一般社団法人
いっぱんしゃだんほうじん
general incorporated association
×1
発表
はっぴょう
announcement; publication; presenting; statement; communique; making known; breaking (news story); expressing (one's opinion); releasing; unveiling
×1
通り
とおり
1. avenue; street; way; road 2. coming and going; street traffic
×1
同梱
どうこん
including (in a package); packing together with
×1
製品
せいひん
manufactured goods; finished goods; product
×1
可能性
かのうせい
potentiality; likelihood; possibility; availability
×1
存在
そんざい
existence; being
×1
有する
ゆうする
to have; to possess; to own; to be endowed with
×1
任意
にんい
1. optional; voluntary; arbitrary; random; discretionary; facultative; spontaneous; any 2. arbitrary
×1
領域
りょういき
area; domain; territory; field; range; region; regime
×1
書き替える
かきかえる
to rewrite; to overwrite; to renew; to transfer
×1
重要
じゅうよう
important; momentous; essential; principal; major
×1
機能
きのう
function; facility; faculty; feature
×1
認証
にんしょう
1. certification; attestation; authentication; confirmation 2. Imperial attestation
×1
欠如
けつじょ
lack; absence; shortage; deficiency; privation
×1
設定ファイル
せっていファイル
setup file
×1
含む
ふくむ
1. to contain; to comprise; to have; to hold; to include; to embrace 2. to hold in the mouth
×1
機微
きび
1. subtleties; niceties; fine points; inner workings; secrets 2. subtle; sensitive
×1
経由
けいゆ
going through; going via; going by way of
×1
読み取る
よみとる
1. to read and understand; to take in 2. to sense from external cues; to read (someone's) mind
×1
送信
そうしん
transmission; sending
×1
許可
きょか
1. permission; approval; authorization; license 2. to permit; to authorize
×1
転送
てんそう
transfer; redirection; transmission; forwarding (telephone call, e-mail, etc.)
×1
もと
1. origin; source 2. base; basis; foundation; root
×1
最新
さいしん
latest; newest; late-breaking (news)
×1
呼び掛ける
よびかける
1. to call out to; to hail; to address 2. to appeal
×1
猶
なお
1. still; yet 2. more; still more; greater; further
×1
推奨
すいしょう
recommendation; endorsement