Critical Fluent Bit bug affects all major cloud providers, say researchers
ID: 927c55c1-b49a-53b9-9587-3c88ae7810fe
STIX ID: report--927c55c1-b49a-53b9-9587-3c88ae7810fe
Feed Name: The Register (Security)
Threat Score
Tenable disclosed CVE-2024-4323 in Fluent Bit (affecting versions 2.0.7–3.0.3), a monitoring-API integer-handling flaw that reliably enables DoS and can leak adjacent memory (partial secrets); RCE is considered possible but environment-dependent and not demonstrated. Tenable published a PoC crash, recommends upgrading to 3.0.4 or limiting/disabling the vulnerable endpoints, and has notified major cloud providers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
