← All CVEs

CVE-2024-4323

critical · 9.8

A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s parsing of trace requests and may result in denial of service conditions, information disclosure, or remote code execution.

9.8
CVSS
27.2%
EPSS (exploit prob.)
98th
EPSS percentile
2024-05-20
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-122CWE-787

Affected products

VendorProductAffected versions
treasuredatafluent_bit>= 2.0.7, < 2.2.3
treasuredatafluent_bit>= 3.0.0, < 3.0.4

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2024-4323