CVE-2024-4323 is a critical memory corruption vulnerability affecting Fluent Bit versions 2.0.7 through 3.0.3, stemming from improper handling of trace requests in its embedded HTTP server. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network without authentication and can lead to denial of service, information disclosure, or remote code execution. While there is no evidence of active exploitation or publicly available exploit code, the vulnerability has garnered significant community attention and media coverage due to its widespread impact on major cloud providers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.7, < 2.2.3CPE matchmatch criteria | cpe:2.3:a:treasuredata:fluent_bit:*:*:*:*:*:*:*:* | ||
>= 3.0.0, < 3.0.4CPE matchmatch criteria | cpe:2.3:a:treasuredata:fluent_bit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2024-4323
Nov 12, 2024NR24-01
Jun 8, 2024NR24-01
Jun 8, 2024Fluent Bit Memory Corruption Vulnerability
May 17, 2024Fluent Bit Memory Corruption Vulnerability
May 14, 2024