Friday, 20 Mar 2026
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Global Market > Fluent Bit vulnerabilities could enable full cloud takeover
Global Market

Fluent Bit vulnerabilities could enable full cloud takeover

Last updated: November 30, 2025 1:23 pm
Published November 30, 2025
Share
Cloud-Security
SHARE

Attackers might flood monitoring programs with false or deceptive occasions, conceal alerts within the noise, and even hijack the telemetry stream solely, Katz stated. The difficulty is now tracked as CVE-2025-12969 and awaits a severity valuation.

Virtually equally troubling are different flaws within the “tag” mechanism, which determines how the data are routed and processed. One bug (CVE-2025-12978) permits an attacker who can guess simply the primary character of the tag key to impersonate trusted tags and reroute logs or bypass filters. One other (CVE-2025-12977) permits unsanitized tag values (together with newlines, directory-traversal strings, and management characters), which might corrupt downstream parsing, allow file-system writes, or permit additional escalation.

Based on the weblog, AWS has secured all of its inner programs that depend on Fluentbit by the Fluentbit mission and launched Fluentbit model 4.1.1. AWS didn’t instantly reply to CSO’s request for remark.

File writes, container overflow, and full agent takeover

Oligo additionally disclosed a sequence of distant code execution (RCE) and path traversal vulnerabilities affecting the device. CVE-2025-12972 targets the “out_file“ output plugin. When Tag values are user-controlled, and no fastened File parameter is ready, attackers can abuse the Tag worth (e.g.,”../“) to trigger path-traversal file writes or overwrites, in the end letting them plant malicious information or achieve RCE.

“Our analysis discovered that a few of these vulnerabilities, corresponding to CVE 2025-12972, have left cloud environments susceptible for over 8 years,” Katz famous.

Within the Docker enter plugin (in-Docker), CVE-2025-12970 reveals a stack buffer overflow. If an attacker names a container with an excessively lengthy identify, the buffer overflow lets them crash the agent or execute code. Oligo warned that the flaw permits attackers to grab the logging agent, conceal their exercise, plant backdoors, and pivot additional into the system.

See also  Cloudflare Extends Server Lifespan to 5 Years, Aligning With Industry Trends

Source link

TAGGED: Bit, cloud, enable, Fluent, full, takeover, vulnerabilities
Share This Article
Twitter Email Copy Link Print
Previous Article Beyond math and coding: New RL framework helps train LLM agents for complex, real-world tasks Beyond math and coding: New RL framework helps train LLM agents for complex, real-world tasks
Next Article Dycom Buys Power Solutions to Deepen Data Center Capabilities
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

DeepGreenX and Veea forge $140B alliance to build AI-powered virtual energy grid

DeepGreenX and hyper-converged multi-access community supplier Veea have fashioned a world strategic partnership to implement…

November 26, 2024

New Nokia calculator helps enterprises lower emissions and improve safety

Nokia not too long ago launched a sustainability calculator goals to assist enterprises in analysing…

September 30, 2024

Meta’s Louisiana Data Center to Cost $50B, Trump Says

(Bloomberg) -- President Donald Trump mentioned that Meta Platforms is planning to spend $50 billion…

September 3, 2025

What are GPUs? Inside the processing power behind AI

AI and generative AI Right this moment’s more and more subtle AI applied sciences —…

April 22, 2025

Chaos Industries Raises $145M in Series B Funding

Chaos Industries, a Los Angeles, CA-based expertise firm constructing new protection and important business applied…

November 14, 2024

You Might Also Like

Cloud Computing Disaster Recovery Solutions Concept - Cloud DR - Services Companies Use for the Purpose of Backing Up Resources into a Cloud Environment - 3D Illustration
Global Market

Nile adds microsegmentation and native NAC to its secure NaaS platform

By saad
Planning delays continue to delay Tritax's Slough data centre
Global Market

Planning delays continue to delay Tritax’s Slough data centre

By saad
A photograph of a row of Ethernet cables plugged into ports, with a warning sign illuminated above one of the ports.
Global Market

Telnet vulnerability opens door to remote code execution as root

By saad
Could Telehouse be about to add a sixth data centre to its Docklands campus?
Global Market

Could Telehouse be about to add a sixth data centre to its Docklands campus?

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.