Experts warn of a flaw in Fluent Bit utility that is used by major cloud platforms and firms
ID: ca7f0609-c853-5940-8388-0a3dd2664e08
STIX ID: report--ca7f0609-c853-5940-8388-0a3dd2664e08
Feed Name: Security Affairs
Threat Score
Tenable disclosed a critical vulnerability (CVE-2024-4323, “Linguistic Lumberjack”) in Fluent Bit’s monitoring API that permits malformed inputs to trigger memory corruption, enabling reliable DoS, intermittent leakage of adjacent memory (including partial secrets), and potentially RCE in some environments; affected versions 2.0.7–3.0.3 are patched in the main branch with a PoC available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
