RubySec

Providing security resources for the Ruby community

CVE-2020-21514 (fluentd-ui): Fluent Fluentd and Fluent-ui use default password

ADVISORIES

GEM

fluentd-ui

SEVERITY

CVSS v3.x: 8.8 (High)

PATCHED VERSIONS

None.

DESCRIPTION

An issue was discovered in Fluent Fluentd v.1.8.0 and Fluent-ui v.1.2.2 that allows attackers to gain escilated privileges and execute arbitrary code due to use of a default password.

RELATED