CVE-2024-4323

Severity CVSS v4.0:
Pending analysis
Type:
CWE-122 Heap-based Buffer Overflow
Publication date:
20/05/2024
Last modified:
05/05/2025

Description

A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s parsing of trace requests and may result in denial of service conditions, information disclosure, or remote code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:treasuredata:fluent_bit:*:*:*:*:*:*:*:* 2.0.7 (including) 2.2.3 (excluding)
cpe:2.3:a:treasuredata:fluent_bit:*:*:*:*:*:*:*:* 3.0.0 (including) 3.0.4 (excluding)