Unrated severityNVD Advisory· Published May 20, 2024· Updated Aug 19, 2024
Fluent Bit Memory Corruption Vulnerability
CVE-2024-4323
Description
A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s parsing of trace requests and may result in denial of service conditions, information disclosure, or remote code execution.
Affected products
8- osv-coords7 versionspkg:apk/chainguard/fluent-bit-3.0pkg:apk/chainguard/fluent-bit-3.0-compatpkg:apk/chainguard/fluent-bit-3.0-devpkg:apk/wolfi/fluent-bit-3.0pkg:apk/wolfi/fluent-bit-3.0-compatpkg:apk/wolfi/fluent-bit-3.0-devpkg:bitnami/fluent-bit
< 3.0.4-r0+ 6 more
- (no CPE)range: < 3.0.4-r0
- (no CPE)range: < 3.0.4-r0
- (no CPE)range: < 3.0.4-r0
- (no CPE)range: < 3.0.4-r0
- (no CPE)range: < 3.0.4-r0
- (no CPE)range: < 3.0.4-r0
- (no CPE)range: >= 2.0.7, < 3.0.4
- Fluent Bit/Fluent Bitv5Range: 2.0.7
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.