Fleet is an open source osquery manager. In Fleet before version 3.7.0 a malicious actor with a valid node key can send a badly formatted request that causes the Fleet server to exit, resulting in denial of service. This is possible only while a live query is currently ongoing. We believe the impact of this vulnerability to be low given the requirement that the actor has a valid node key. There is no information disclosure, privilege escalation, or code execution. The issue is fixed in Fleet 3.7.0.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-8657 Fleet is an open source osquery manager. In Fleet before version 3.7.0 a malicious actor with a valid node key can send a badly formatted request that causes the Fleet server to exit, resulting in denial of service. This is possible only while a live query is currently ongoing. We believe the impact of this vulnerability to be low given the requirement that the actor has a valid node key. There is no information disclosure, privilege escalation, or code execution. The issue is fixed in Fleet 3.7.0.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-03T18:09:15.667Z

Reserved: 2020-12-22T00:00:00

Link: CVE-2021-21296

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-02-10T20:15:15.353

Modified: 2024-11-21T05:47:57.893

Link: CVE-2021-21296

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.