CVE-2024-23722

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-23722
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-23722.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-23722
Aliases
Related
Published
2024-03-26T15:15:49Z
Modified
2025-01-08T09:48:09.815542Z
Summary
[none]
Details

In Fluent Bit 2.1.8 through 2.2.1, a NULL pointer dereference can be caused via an invalid HTTP payload with the content type of x-www-form-urlencoded. It crashes and does not restart. This could result in logs not being delivered properly.

References

Affected packages

Git / github.com/fluent/fluent-bit

Affected ranges

Type
GIT
Repo
https://github.com/fluent/fluent-bit
Events

Affected versions

v2.*

v2.1.10
v2.1.8
v2.1.9
v2.2.0
v2.2.1