CVE-2017-10906: Fluentd

Critical severity, CVSS 9.8. EPSS: 4.6% chance of exploitation in the next 30 days.

Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execute arbitrary commands on the device via unspecified vectors.

Affected products

  • Fluentd Fluentd: version 0.12.29 only; version 0.12.30 only; version 0.12.31 only; version 0.12.32 only; version 0.12.33 only; version 0.12.34 only; …
  • Red Hat Openstack: version 13 only

Published 2017-12-08. Last modified 2026-06-17.