PT-2024-20035 · Unknown+2 · Fluent-Bit+2
Published
2024-03-25
·
Updated
2025-02-03
·
CVE-2024-23722
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Fluent Bit versions 2.1.8 through 2.2.1
Description
A NULL pointer dereference can be caused via an invalid HTTP payload with the content type of x-www-form-urlencoded, resulting in a crash and failure to restart. This could lead to logs not being delivered properly.
Recommendations
For Fluent Bit versions 2.1.8 through 2.2.1, as a temporary workaround, consider restricting the use of HTTP payloads with the content type of x-www-form-urlencoded to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fluent-Bit
Linuxmint
Ubuntu