Description
A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s parsing of trace requests and may result in denial of service conditions, information disclosure, or remote code execution.
Published: 2024-05-20
Score: 9.8 Critical
EPSS: 84.8% High
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

A fix for this issue is introduced in versions 2.2.3 and 3.0.4.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.76357}

epss

{'score': 0.78837}


Mon, 05 May 2025 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Treasuredata
Treasuredata fluent Bit
Weaknesses CWE-787
CPEs cpe:2.3:a:treasuredata:fluent_bit:*:*:*:*:*:*:*:*
Vendors & Products Treasuredata
Treasuredata fluent Bit

Mon, 19 Aug 2024 08:30:00 +0000


Subscriptions

Treasuredata Fluent Bit
cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2024-08-19T07:47:45.924Z

Reserved: 2024-04-29T18:39:50.531Z

Link: CVE-2024-4323

cve-icon Vulnrichment

Updated: 2024-08-19T07:47:45.924Z

cve-icon NVD

Status : Analyzed

Published: 2024-05-20T12:15:08.720

Modified: 2025-05-05T17:03:14.350

Link: CVE-2024-4323

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses