The critical Fluent Bit , which can be exploited in attacks , affects all major cloud providers and many tech giants.
See also: Wi-Fi vulnerability allows tracking of users' online movements

Fluent Bit is an extremely popular logging and metrics solution for Windows , Linux , and macOS integrated into major Kubernetes distributions , including those of Amazon AWS, Google GCP, and Microsoft Azure .
By March 2024, Fluent Bit had been downloaded and deployed over 13 billion times, a huge increase from the three billion downloads reported in October 2022. Fluent Bit is also used by cybersecurity companies such as Crowdstrike and Trend Micro, and many technology companies, including Cisco ,, VMware, Intel, Adobe and Dell.
Known as CVE-2024-4323 or Linguistic Lumberjack by the Tenable security researchers who discovered it, this critical memory corruption flaw was introduced with version 2.0.7 and is caused by a buffer overflow vulnerability in the parsing of monitoring requests by Fluent Bit's built-in HTTP server.
Although unverified attackers can easily exploit the security flaw to trigger a denial of service or remotely capture sensitive information, they could also use it to perform remote code execution if given the right conditions and enough time to create a credible exploit.
See also: PoC exploit released for RCE zero-day on DIR-X4860 routers
" While buffer overflows like this are known to be exploitable, creating a reliable exploit is not only difficult, but also incredibly time-consuming ," Tenable said

Submitting patches with Fluent Bit 3.0.4
Tenable reported the security flaw to the vendor on April 30 , and fixes were reported to the Fluent Bit master branch on May 15. Official releases containing this patch are expected to ship with Fluent Bit 3.0.4.
Tenable also notified Microsoft, Amazon , and Google of this critical security flaw on May 15th via their vulnerability disclosure platforms.
Until fixes are available for all affected platforms, customers who have deployed this logging utility on their own infrastructure can mitigate the issue by restricting access to the Fluent Bit monitoring API to authorized users and services.
You can also disable this vulnerable API endpoint if it is not being used to ensure that any potential attacks are blocked and the attack surface is removed.
See also: Apple fixes Safari WebKit zero-day flaw
One of the most effective methods for finding defects, such as Fluent Bit's, is code analysis. This analysis can be either static or dynamic. Static analysis involves examining the source code without executing it, while dynamic analysis involves executing the code in a controlled environment to detect potential weaknesses. Penetration testing is another critical method. Security experts attempt to penetrate the system using various techniques, simulating attacks that could be carried out by malicious users. The use of automated vulnerability scanning tools is also important. These tools can scan large systems and networks for known vulnerabilities, providing quick results and suggestions for addressing them.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: bleepingcomputer
