CVE-2024-4323
CRITICAL 9.8EPSS 28.3%
A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s parsing of trace requests and may result in denial of service conditions, information disclosure, or remote code execution.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 28.31% chance of exploitation in the next 30 days, 98th percentile
- Published
- 2024-05-20
- Updated
- 2024-08-19
Proof-of-concept exploits (4)
- https://www.vicarius.io/vsociety/posts/linguistic-lumberjack-memory-corruption-in-fluent-…
- d0rb/CVE-2024-43231★ · 2024-05-21
- skilfoy/CVE-2024-4323-Exploit-POC15★ · 2024-05-20
- yuansec/CVE-2024-4323-dos_poc0★ · 2024-05-22