Treasuredata

Fluent Bit

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.67%
  • Veröffentlicht 26.03.2024 15:15:49
  • Zuletzt bearbeitet 30.04.2025 16:48:32

In Fluent Bit 2.1.8 through 2.2.1, a NULL pointer dereference can be caused via an invalid HTTP payload with the content type of x-www-form-urlencoded. It crashes and does not restart. This could result in logs not being delivered properly.

Exploit
  • EPSS 0.07%
  • Veröffentlicht 26.02.2024 18:15:07
  • Zuletzt bearbeitet 12.05.2025 12:57:01

fluent-bit 2.2.2 contains a Use-After-Free vulnerability in /fluent-bit/plugins/custom_calyptia/calyptia.c.

Exploit
  • EPSS 0.03%
  • Veröffentlicht 11.04.2023 18:15:58
  • Zuletzt bearbeitet 11.02.2025 20:15:31

An issue was discovered in Treasure Data Fluent Bit 1.7.1, a wrong variable is used to get the msgpack data resulting in a heap overflow in flb_msgpack_gelf_value_ext. An attacker can craft a malicious file and tick the victim to open the file with t...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 11.04.2023 18:15:58
  • Zuletzt bearbeitet 11.02.2025 21:15:08

An issue was discovered in Treasure Data Fluent Bit 1.7.1, erroneous parsing in flb_pack_msgpack_to_json_format leads to type confusion bug that interprets whatever is on the stack as msgpack maps and arrays, leading to use-after-free. This can be us...

Exploit
  • EPSS 0.51%
  • Veröffentlicht 01.07.2021 03:15:08
  • Zuletzt bearbeitet 21.11.2024 06:13:07

Fluent Bit (aka fluent-bit) 1.7.0 through 1.7.4 has a double free in flb_free (called from flb_parser_json_do and flb_parser_do).

Exploit
  • EPSS 0.41%
  • Veröffentlicht 10.02.2021 22:15:13
  • Zuletzt bearbeitet 21.11.2024 05:57:31

Fluent Bit 1.6.10 has a NULL pointer dereference when an flb_malloc return value is not validated by flb_avro.c or http_server/api/v1/metrics.c.

Exploit
  • EPSS 0.38%
  • Veröffentlicht 03.01.2021 19:15:11
  • Zuletzt bearbeitet 21.11.2024 05:28:36

flb_gzip_compress in flb_gzip.c in Fluent Bit before 1.6.4 has an out-of-bounds write because it does not use the correct calculation of the maximum gzip data-size expansion.

Exploit
  • EPSS 1.01%
  • Veröffentlicht 13.03.2019 19:29:00
  • Zuletzt bearbeitet 21.11.2024 04:52:13

An issue was discovered in the MQTT input plugin in Fluent Bit through 1.0.4. When this plugin acts as an MQTT broker (server), it mishandles incoming network messages. After processing a crafted packet, the plugin's mqtt_packet_drop function (in /pl...