fluent.fluent-bit is vulnerable to Use-After-Free
15
Low Risk
Affected versions of the fluent.fluent-bit plugin are vulnerable to a use-after-free bug in the flb_plugin_load_config_file function. This issue occurs while loading plugins from a configuration file and was introduced in version 3.2.0 with the addition of YAML support. A use-after-free vulnerability arises when a program continues to use memory that has already been freed, potentially leading to undefined behavior, memory corruption, or exploitation.
You are affected if you are using a version that falls within the vulnerable range.
fluent.fluent-bit is vulnerable to Use-After-Free in versions 3.2.0 - 3.2.1.
Upgrade the fluent.fluent-bit library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant