Popular telemetry agent Fluent Bit has been impacted by multiple critical security issues, underscoring significant risks to financial services and software-as-a-service environments, as well as security tools and delivery apps, Infosecurity Magazine reports.Improper input validation, path traversal, partial string comparison, authentication bypass, and stack buffer overflow vulnerabilities stemming from failed sanitization were present in Fluent Bit versions older than 4.1.1 and 4.0.12, according to Oligo Security researchers. Attackers could leverage such flaws to facilitate log redirection, dataset poisoning, code execution, and sensitive file overwriting, as well as affect system stability, said researchers, who warned of even more serious compromise if chained alongside each other.Organizations have been advised not only to promptly implement the latest iterations of Fluent Bit that address the bugs but also to lock down output file parameters, prevent dynamic tags in routing, adopt least-privilege access, and establish read-only configuration directories.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
