A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s parsing of trace requests and may result in denial of service conditions, information disclosure, or remote code execution.
References
| Link | Resource |
|---|---|
| https://github.com/fluent/fluent-bit/commit/9311b43a258352797af40749ab31a63c32acfd04 | Patch |
| https://tenable.com/security/research/tra-2024-17 | Patch Third Party Advisory |
| https://github.com/fluent/fluent-bit/commit/9311b43a258352797af40749ab31a63c32acfd04 | Patch |
| https://tenable.com/security/research/tra-2024-17 | Patch Third Party Advisory |
| https://www.vicarius.io/vsociety/posts/linguistic-lumberjack-memory-corruption-in-fluent-bit-cve-2024-4323 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-05-20 12:15
Updated : 2025-05-05 17:03
NVD link : CVE-2024-4323
Mitre link : CVE-2024-4323
CVE.ORG link : CVE-2024-4323
JSON object : View
Products Affected
treasuredata
- fluent_bit
