fluent / helm-charts

Helm Charts for Fluentd and Fluent Bit
Apache License 2.0
375 stars 448 forks source link

Patches shipping with Fluent Bit 3.0.4 #507

Closed ericshiu closed 4 months ago

ericshiu commented 4 months ago

Tracked as CVE-2024-4323 and dubbed Linguistic Lumberjack by Tenable security researchers who discovered it, this critical memory corruption vulnerability was introduced with version 2.0.7 and is caused by a heap buffer overflows weakness in Fluent Bit's embedded HTTP server's parsing of trace requests.

patrick-stephens commented 4 months ago

508 will explicitly update this, however the helm chart by default should pull the latest image and you can override it too

patrick-stephens commented 4 months ago

Resolved in #508