* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Thursday, June 5, 2025
Earth-News
  • Home
  • Business
  • Entertainment
  • General
  • Health
  • News

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
  • General
  • Health
  • News

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Critical Fluent Bit flaw impacts all major cloud providers

May 21, 2024
in Technology
Critical Fluent Bit flaw impacts all major cloud providers
Share on FacebookShare on Twitter

Cloud Hacker

​A critical Fluent Bit vulnerability that can be exploited in denial-of-service and remote code execution attacks impacts all major cloud providers and many technology giants.

Fluent Bit is an extremely popular logging and metrics solution for Windows, Linux, and macOS embedded in major Kubernetes distributions, including those from Amazon AWS, Google GCP, and Microsoft Azure.

Until March 2024, Fluent Bit was downloaded and deployed over 13 billion times, a massive increase from the three billion downloads reported in October 2022.

Fluent Bit is also used by cybersecurity firms like Crowdstrike and Trend Micro, and many tech companies, such as Cisco, VMware, Intel, Adobe, and Dell.

Tracked as CVE-2024-4323 and dubbed Linguistic Lumberjack by Tenable security researchers who discovered it, this critical memory corruption vulnerability was introduced with version 2.0.7 and is caused by a heap buffer overflows weakness in Fluent Bit’s embedded HTTP server’s parsing of trace requests.

Even though unauthenticated attackers can easily exploit the security flaw to trigger denial-of-service or to capture sensitive information remotely, they could also use it to gain remote code execution if given the right conditions and enough time to create a reliable exploit.

“While heap buffer overflows such as this are known to be exploitable, creating a reliable exploit is not only difficult, but incredibly time intensive,” Tenable said.

“The researchers believe that the most immediate and primary risks are those pertaining to the ease with which DoS and information leaks can be accomplished.”

Patches shipping with Fluent Bit 3.0.4

Tenable reported the security bug to the vendor on April 30, and fixes were committed to Fluent Bit’s main branch on May 15. Official releases containing this patch are expected to ship with Fluent Bit 3.0.4 (Linux packages are available here).

Tenable also notified Microsoft, Amazon, and Google of this critical security bug on May 15 through their vulnerability disclosure platforms.

Until fixes are available for all impacted platforms, customers who have deployed this logging utility on their own infrastructure can mitigate the issue by limiting access to Fluent Bit’s monitoring API to authorized users and services.

You can also disable this vulnerable API endpoint if it’s not being used to ensure that any potential attacks are blocked and the attack surface is removed.

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : BleepingComputer – https://www.bleepingcomputer.com/news/security/critical-fluent-bit-flaw-impacts-all-major-cloud-providers/

Tags: criticalFluenttechnology
Previous Post

OmniVision discloses data breach after 2023 ransomware attack

Next Post

AI models can outperform humans in tests to identify mental states

The Ecology of Visitation – National Park Service (.gov)

Exploring the Impact of Visitor Interactions on Natural Ecosystems

June 5, 2025
Students play with science at Camp Invention at School of Innovation – News-Herald

Unleashing Creativity: Students Dive into Science at Camp Invention!

June 5, 2025
Are cold plunges good for you? Here’s what the science says. – The Washington Post

Unlocking the Benefits of Cold Plunges: What Science Reveals!

June 5, 2025
Casino magnate Alvin Chau’s wife Heidi Chan embraces Buddhist lifestyle after husband’s incarceration – VnExpress International

Casino magnate Alvin Chau’s wife Heidi Chan embraces Buddhist lifestyle after husband’s incarceration – VnExpress International

June 5, 2025
How each of the 32 teams qualified for the 2025 Club World Cup – The New York Times

Unveiling the Path: How All 32 Teams Earned Their Spot in the 2025 Club World Cup

June 5, 2025
Service side of the U.S. economy contracts for first time in almost a year due to trade fights – MarketWatch

U.S. Service Sector Shrinks for the First Time in Nearly a Year Amid Trade Tensions

June 5, 2025
‘Sinners,’ starring Michael B. Jordan, is now streaming on Prime Video – About Amazon

Experience the Thrills of ‘Sinners’ Starring Michael B. Jordan – Now Streaming on Prime Video!

June 5, 2025
Sutter Health investing $23 million in primary and behavioral care – Healthcare Finance News

Sutter Health investing $23 million in primary and behavioral care – Healthcare Finance News

June 5, 2025
Gov. Shapiro sues USDA over canceled $13M food purchasing program – LancasterOnline

Gov. Shapiro sues USDA over canceled $13M food purchasing program – LancasterOnline

June 5, 2025
Domo to Participate in the D.A. Davidson Technology Summit – Business Wire

Domo Set to Shine at the D.A. Davidson Technology Summit!

June 5, 2025

Categories

Archives

June 2025
MTWTFSS
 1
2345678
9101112131415
16171819202122
23242526272829
30 
« May    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (667)
  • Economy (681)
  • Entertainment (21,587)
  • General (15,261)
  • Health (9,723)
  • Lifestyle (684)
  • News (22,149)
  • People (682)
  • Politics (690)
  • Science (15,901)
  • Sports (21,185)
  • Technology (15,667)
  • World (668)

Recent News

The Ecology of Visitation – National Park Service (.gov)

Exploring the Impact of Visitor Interactions on Natural Ecosystems

June 5, 2025
Students play with science at Camp Invention at School of Innovation – News-Herald

Unleashing Creativity: Students Dive into Science at Camp Invention!

June 5, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version