An issue was discovered in Fluent-ui v.1.2.2 allows attackers to gain escalated privileges and execute arbitrary code due to a default password.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://github.com/fluent/fluentd/issues/2722 | exploit issue tracking |
https://github.com/fluent/fluentd-ui/issues/295 |