A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s parsing of trace requests and may result in denial of service conditions, information disclosure, or remote code execution.
References
Link | Resource |
---|---|
https://github.com/fluent/fluent-bit/commit/9311b43a258352797af40749ab31a63c32acfd04 | Patch |
https://tenable.com/security/research/tra-2024-17 | Patch Third Party Advisory |
https://github.com/fluent/fluent-bit/commit/9311b43a258352797af40749ab31a63c32acfd04 | Patch |
https://tenable.com/security/research/tra-2024-17 | Patch Third Party Advisory |
https://www.vicarius.io/vsociety/posts/linguistic-lumberjack-memory-corruption-in-fluent-bit-cve-2024-4323 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
05 May 2025, 17:03
Type | Values Removed | Values Added |
---|---|---|
First Time |
Treasuredata
Treasuredata fluent Bit |
|
CWE | CWE-787 | |
CPE | cpe:2.3:a:treasuredata:fluent_bit:*:*:*:*:*:*:*:* | |
References | () https://github.com/fluent/fluent-bit/commit/9311b43a258352797af40749ab31a63c32acfd04 - Patch | |
References | () https://tenable.com/security/research/tra-2024-17 - Patch, Third Party Advisory | |
References | () https://www.vicarius.io/vsociety/posts/linguistic-lumberjack-memory-corruption-in-fluent-bit-cve-2024-4323 - Exploit, Third Party Advisory |
21 Nov 2024, 09:42
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References |
|
|
References | () https://github.com/fluent/fluent-bit/commit/9311b43a258352797af40749ab31a63c32acfd04 - | |
References | () https://tenable.com/security/research/tra-2024-17 - |
20 May 2024, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-05-20 12:15
Updated : 2025-05-05 17:03
NVD link : CVE-2024-4323
Mitre link : CVE-2024-4323
CVE.ORG link : CVE-2024-4323
JSON object : View
Products Affected
treasuredata
- fluent_bit