CVE-2020-28169: Debian Linux

High severity, CVSS 7.0. EPSS: 1.2% chance of exploitation in the next 30 days.

The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory is writable by a user account, but a file in bin is executed as NT AUTHORITY\SYSTEM.

Affected products

Published 2020-12-24. Last modified 2026-06-17.