PT-2024-20035 · Unknown+2 · Fluent-Bit+2

Published

2024-03-25

·

Updated

2025-02-03

·

CVE-2024-23722

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Fluent Bit versions 2.1.8 through 2.2.1
Description A NULL pointer dereference can be caused via an invalid HTTP payload with the content type of x-www-form-urlencoded, resulting in a crash and failure to restart. This could lead to logs not being delivered properly.
Recommendations For Fluent Bit versions 2.1.8 through 2.2.1, as a temporary workaround, consider restricting the use of HTTP payloads with the content type of x-www-form-urlencoded to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

AZL-37083
BDU:2025-02748
BIT-FLUENT-BIT-2024-23722
CVE-2024-23722
USN-7250-1

Affected Products

Fluent-Bit
Linuxmint
Ubuntu