PT-2021-21109 · Unknown · Fluent-Bit

David Korczynski

·

Published

2021-07-01

·

Updated

2024-07-03

·

CVE-2021-36088

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Fluent Bit (aka fluent-bit) versions 1.7.0 through 1.7.4
Description: The issue is related to a double free in the flb free function, which is called from flb parser json do and flb parser do.
Recommendations: For Fluent Bit (aka fluent-bit) versions 1.7.0 through 1.7.4, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Double Free

Weakness Enumeration

Related Identifiers

BIT-FLUENT-BIT-2021-36088
CVE-2021-36088

Affected Products

Fluent-Bit