CVE-2024-4323

A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s parsing of trace requests and may result in denial of service conditions, information disclosure, or remote code execution.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:treasuredata:fluent_bit:*:*:*:*:*:*:*:*
cpe:2.3:a:treasuredata:fluent_bit:*:*:*:*:*:*:*:*

History

05 May 2025, 17:03

Type Values Removed Values Added
First Time Treasuredata
Treasuredata fluent Bit
CWE CWE-787
CPE cpe:2.3:a:treasuredata:fluent_bit:*:*:*:*:*:*:*:*
References () https://github.com/fluent/fluent-bit/commit/9311b43a258352797af40749ab31a63c32acfd04 - () https://github.com/fluent/fluent-bit/commit/9311b43a258352797af40749ab31a63c32acfd04 - Patch
References () https://tenable.com/security/research/tra-2024-17 - () https://tenable.com/security/research/tra-2024-17 - Patch, Third Party Advisory
References () https://www.vicarius.io/vsociety/posts/linguistic-lumberjack-memory-corruption-in-fluent-bit-cve-2024-4323 - () https://www.vicarius.io/vsociety/posts/linguistic-lumberjack-memory-corruption-in-fluent-bit-cve-2024-4323 - Exploit, Third Party Advisory

21 Nov 2024, 09:42

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de corrupción de memoria en las versiones 2.0.7 a 3.0.3 de Fluent Bit. Este problema radica en el análisis de las solicitudes de seguimiento por parte del servidor http integrado y puede dar lugar a condiciones de denegación de servicio, divulgación de información o ejecución remota de código.
References
  • () https://www.vicarius.io/vsociety/posts/linguistic-lumberjack-memory-corruption-in-fluent-bit-cve-2024-4323 -
References () https://github.com/fluent/fluent-bit/commit/9311b43a258352797af40749ab31a63c32acfd04 - () https://github.com/fluent/fluent-bit/commit/9311b43a258352797af40749ab31a63c32acfd04 -
References () https://tenable.com/security/research/tra-2024-17 - () https://tenable.com/security/research/tra-2024-17 -

20 May 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-20 12:15

Updated : 2025-05-05 17:03


NVD link : CVE-2024-4323

Mitre link : CVE-2024-4323

CVE.ORG link : CVE-2024-4323


JSON object : View

Products Affected

treasuredata

  • fluent_bit
CWE
CWE-122

Heap-based Buffer Overflow

CWE-787

Out-of-bounds Write