A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s parsing of trace requests and may result in denial of service conditions, information disclosure, or remote code execution.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/fluent/fluent-bit/commit/9311b43a258352797af40749ab31a63c32acfd04 | Patch | 
| https://tenable.com/security/research/tra-2024-17 | Patch Third Party Advisory | 
| https://github.com/fluent/fluent-bit/commit/9311b43a258352797af40749ab31a63c32acfd04 | Patch | 
| https://tenable.com/security/research/tra-2024-17 | Patch Third Party Advisory | 
| https://www.vicarius.io/vsociety/posts/linguistic-lumberjack-memory-corruption-in-fluent-bit-cve-2024-4323 | Exploit Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    05 May 2025, 17:03
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time | Treasuredata Treasuredata fluent Bit | |
| CWE | CWE-787 | |
| CPE | cpe:2.3:a:treasuredata:fluent_bit:*:*:*:*:*:*:*:* | |
| References | () https://github.com/fluent/fluent-bit/commit/9311b43a258352797af40749ab31a63c32acfd04 - Patch | |
| References | () https://tenable.com/security/research/tra-2024-17 - Patch, Third Party Advisory | |
| References | () https://www.vicarius.io/vsociety/posts/linguistic-lumberjack-memory-corruption-in-fluent-bit-cve-2024-4323 - Exploit, Third Party Advisory | 
21 Nov 2024, 09:42
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | |
| References | 
 | |
| References | () https://github.com/fluent/fluent-bit/commit/9311b43a258352797af40749ab31a63c32acfd04 - | |
| References | () https://tenable.com/security/research/tra-2024-17 - | 
20 May 2024, 12:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-05-20 12:15
Updated : 2025-05-05 17:03
NVD link : CVE-2024-4323
Mitre link : CVE-2024-4323
CVE.ORG link : CVE-2024-4323
JSON object : View
Products Affected
                treasuredata
- fluent_bit
