CVE-2024-4323
9.8
CRITICAL · CVSS 3.1 · EPSS 27.2% (pctl 98)
Patch early
EPSS 27.2% — above the 10% action threshold.
Description
A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s parsing of trace requests and may result in denial of service conditions, information disclosure, or remote code execution.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 27.24% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-122 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2024-05-20 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| treasuredata | fluent bit |
References
- https://github.com/fluent/fluent-bit/commit/9311b43a258352797af40749ab31a63c32acfd04
- https://tenable.com/security/research/tra-2024-17
- https://github.com/fluent/fluent-bit/commit/9311b43a258352797af40749ab31a63c32acfd04
- https://tenable.com/security/research/tra-2024-17
- https://www.vicarius.io/vsociety/posts/linguistic-lumberjack-memory-corruption-in-fluent-bit-cve-2024-4323
→ the Explorer · watch your stack · NVD