The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory is writable by a user account, but a file in bin is executed as NT AUTHORITY\SYSTEM.
References
Configurations
History
No history.
Information
Published : 2020-12-24 15:15
Updated : 2024-11-21 05:22
NVD link : CVE-2020-28169
Mitre link : CVE-2020-28169
CVE.ORG link : CVE-2020-28169
JSON object : View
Products Affected
microsoft
- windows
debian
- debian_linux
td-agent-builder_project
- td-agent-builder
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource