CVE-2024-4323

A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s parsing of trace requests and may result in denial of service conditions, information disclosure, or remote code execution.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:treasuredata:fluent_bit:*:*:*:*:*:*:*:*
cpe:2.3:a:treasuredata:fluent_bit:*:*:*:*:*:*:*:*

History

05 May 2025, 17:03

Type Values Removed Values Added
References () https://github.com/fluent/fluent-bit/commit/9311b43a258352797af40749ab31a63c32acfd04 - () https://github.com/fluent/fluent-bit/commit/9311b43a258352797af40749ab31a63c32acfd04 - Patch
References () https://tenable.com/security/research/tra-2024-17 - () https://tenable.com/security/research/tra-2024-17 - Patch, Third Party Advisory
References () https://www.vicarius.io/vsociety/posts/linguistic-lumberjack-memory-corruption-in-fluent-bit-cve-2024-4323 - () https://www.vicarius.io/vsociety/posts/linguistic-lumberjack-memory-corruption-in-fluent-bit-cve-2024-4323 - Exploit, Third Party Advisory
CWE CWE-787
CPE cpe:2.3:a:treasuredata:fluent_bit:*:*:*:*:*:*:*:*
First Time Treasuredata fluent Bit
Treasuredata

Information

Published : 2024-05-20 12:15

Updated : 2025-05-05 17:03


NVD link : CVE-2024-4323

Mitre link : CVE-2024-4323

CVE.ORG link : CVE-2024-4323


JSON object : View

Products Affected

treasuredata

  • fluent_bit
CWE
CWE-122

Heap-based Buffer Overflow

CWE-787

Out-of-bounds Write