A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s parsing of trace requests and may result in denial of service conditions, information disclosure, or remote code execution.
References
Link | Resource |
---|---|
https://github.com/fluent/fluent-bit/commit/9311b43a258352797af40749ab31a63c32acfd04 | Patch |
https://github.com/fluent/fluent-bit/commit/9311b43a258352797af40749ab31a63c32acfd04 | Patch |
https://tenable.com/security/research/tra-2024-17 | Patch Third Party Advisory |
https://tenable.com/security/research/tra-2024-17 | Patch Third Party Advisory |
https://www.vicarius.io/vsociety/posts/linguistic-lumberjack-memory-corruption-in-fluent-bit-cve-2024-4323 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
05 May 2025, 17:03
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-787 | |
CPE | cpe:2.3:a:treasuredata:fluent_bit:*:*:*:*:*:*:*:* | |
First Time |
Treasuredata
Treasuredata fluent Bit |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
References |
|
|
References | () https://tenable.com/security/research/tra-2024-17 - Patch, Third Party Advisory | |
References | () https://github.com/fluent/fluent-bit/commit/9311b43a258352797af40749ab31a63c32acfd04 - Patch |
20 May 2024, 13:00
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-05-20 12:15
Updated : 2025-05-05 17:03
NVD link : CVE-2024-4323
Mitre link : CVE-2024-4323
JSON object : View
Products Affected
treasuredata
- fluent_bit
CWE
CWE-787
Out-of-bounds Write