CVE-2024-4323
Fluent Bit Memory Corruption Vulnerability
9.8
CRITICAL
CVSS 3.1
EPSS 28.3%
Description
A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s parsing of trace requests and may result in denial of service conditions, information disclosure, or remote code execution.
How to fix CVE-2024-4323
To remediate CVE-2024-4323, upgrade the affected package to a fixed version below.
- Bitnami/fluent-bit—upgrade to 3.0.4 or later
Is CVE-2024-4323 being exploited?
Moderate — EPSS is 28.3%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- >= 2.0.7, < 3.0.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |