Tag: vulnerability in Fluent Bit

“Linguistic Lumberjack” Vulnerability Discovered in Popular Logging Utility Fluent Bit
News

“Linguistic Lumberjack” Vulnerability Discovered in Popular Logging Utility Fluent Bit

Researchers studying cybersecurity have uncovered a serious security vulnerability in Fluent Bit, a well-known logging and analytics tool. This vulnerability might be used to cause denial-of-service (DoS), expose confidential information, or execute code remotely. Tenable Research has given the vulnerability, which is tracked as CVE-2024-4323, the codename Linguistic Lumberjack. Version 3.0.4 has the fixes for versions 2.0.7 through 3.0.3 that are affected. The problem is related to a memory corruption event that could enable remote code execution, DoS attacks, or information leaking in Fluent Bit's integrated HTTP server. It is specifically related to using endpoints like /api/v1/traces and /api/v1/trace to submit maliciously constructed queries to the monitoring API read more L...