Deserialization of Untrusted Data in Fluentd - CVE-2022-39379
Published: September 22, 2025
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data if the environment variable "FLUENT_OJ_OPTION_MODE" is explicitly set to "object". A remote user can pass specially crafted data to the application and execute arbitrary code on the target system.
Affected software
openEuler
Fedora
rubygem-fluentd
rubygem-fluentd-help
golang-github-graylog2-gelf
golang-github-docker
How to mitigate CVE-2022-39379
rubygem-fluentd - update to 1.14.5-3
rubygem-fluentd-help - update to 1.14.5-3
golang-github-graylog2-gelf - update to 2.0.0-6.20201111git1550ee6.fc37
golang-github-docker - update to 22.06.0~beta.0-7.fc37