CVE Published: 20/05/2024 |
CVE Updated: 19/08/2024 |
CVE Year: 2024 Source: tenable |
Vendor: Fluent Bit |
Product: Fluent Bit Status : PUBLISHED
CVE-2024-4323 Description
A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s parsing of trace requests and may result in denial of service conditions, information disclosure, or remote code execution.
Metrics
CVSS Version: 3.1 |
Base Score: 9.8 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H