CVE-2024-4323Linguistic Lumberjack: Heap-based Buffer Overflow in Fluent BIT

Severity
9.8CRITICALNVD
EPSS
84.6%
top 0.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 20

Description

A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s parsing of trace requests and may result in denial of service conditions, information disclosure, or remote code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Patches

🔴Vulnerability Details

1
GHSA
GHSA-68mr-468g-4wmg: A memory corruption vulnerability in Fluent Bit versions 22024-05-20

📋Vendor Advisories

1
Microsoft
Fluent Bit Memory Corruption Vulnerability2024-05-14

🕵️Threat Intelligence

3
Bleepingcomputer
Critical Fluent Bit flaw impacts all major cloud providers2024-05-20
Tenable
Linguistic Lumberjack: Attacking Cloud Services via Logging Endpoints (Fluent Bit - CVE-2024-4323)2024-05-20
Greynoiseio
NoiseLetter May 2024

💬Community

1
Bugzilla
CVE-2017-12839 mpg123: heap-based buffer over-read in function getbits insrc/libmpg123/getbits.h2019-05-10
CVE-2024-4323 — Linguistic Lumberjack | cvebase