CVE-2024-4323

A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s parsing of trace requests and may result in denial of service conditions, information disclosure, or remote code execution.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:treasuredata:fluent_bit:*:*:*:*:*:*:*:*
cpe:2.3:a:treasuredata:fluent_bit:*:*:*:*:*:*:*:*

History

05 May 2025, 17:03

Type Values Removed Values Added
CWE CWE-787
CPE cpe:2.3:a:treasuredata:fluent_bit:*:*:*:*:*:*:*:*
First Time Treasuredata
Treasuredata fluent Bit
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References
  • () https://www.vicarius.io/vsociety/posts/linguistic-lumberjack-memory-corruption-in-fluent-bit-cve-2024-4323 - Exploit, Third Party Advisory
References () https://tenable.com/security/research/tra-2024-17 - () https://tenable.com/security/research/tra-2024-17 - Patch, Third Party Advisory
References () https://github.com/fluent/fluent-bit/commit/9311b43a258352797af40749ab31a63c32acfd04 - () https://github.com/fluent/fluent-bit/commit/9311b43a258352797af40749ab31a63c32acfd04 - Patch

20 May 2024, 13:00

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-20 12:15

Updated : 2025-05-05 17:03


NVD link : CVE-2024-4323

Mitre link : CVE-2024-4323


JSON object : View

Products Affected

treasuredata

  • fluent_bit
CWE
CWE-787

Out-of-bounds Write