Tuesday, 10 Feb 2026
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Design > Critical Bug Allows DoS, RCE, Data Leaks in All Major Cloud Platforms
Design

Critical Bug Allows DoS, RCE, Data Leaks in All Major Cloud Platforms

Last updated: May 31, 2024 4:36 pm
Published May 31, 2024
Share
Critical Bug Allows DoS, RCE, Data Leaks in All Major Cloud Platforms
SHARE

Researchers have found a extreme reminiscence corruption vulnerability inside a cloud logging utility used throughout main cloud platforms.

The service, Fluent Bit, is an open supply software for gathering, processing, and forwarding logs and different sorts of software information. It is one of many extra well-liked items of software program on the market, with greater than three billion downloads as of 2022, and a brand new 10 million or so deployments with every passing day. It is utilized by main organizations equivalent to VMware, Cisco, Adobe, Walmart, and LinkedIn, and almost each main cloud service supplier, together with AWS, Microsoft, and Google Cloud.

The difficulty with Fluent Bit, dubbed “Linguistic Lumberjack” in a new report from Tenable, lies in how the service’s embedded HTTP server parses hint requests. Manipulated in a technique or one other, it might trigger denial of service (DoS), information leakage, or distant code execution (RCE) in a cloud surroundings.

“Everybody will get hyped a few vulnerability in Azure, AWS, GCP, however no one’s actually wanting on the applied sciences that make up all of those main cloud companies – widespread, core items of software program that now have an effect on each main cloud supplier,” says Jimi Sebree, senior employees analysis engineer with Tenable. “It’s essential to be in search of software safety bombs and like parts of the companies, not simply the companies themselves.”

The Linguistic Lumberjack Impact

Tenable researchers initially had been wanting into a wholly separate safety situation in an undisclosed cloud service after they realized one thing sudden was occurring. From the place they had been sitting, it appeared they had been capable of entry a variety of the cloud service supplier’s (CSP) personal inside metrics and logging endpoints. Amongst these had been situations of Fluent Bit.

See also  Portus Data Centers welcomes Richard Pimper as COO & CTO

This cross-tenant information leakage got here from endpoints in Fluent Bit’s monitoring software programming interface (API), designed to permit customers to question and monitor its inside information. After some testing, although, a little bit of leaky information turned out to be solely the introduction to a deeper downside.

For a specific endpoint – /api/v1/traces – the sorts of information handed as enter names weren’t correctly validated previous to being parsed by this system. So by passing non-string values, an attacker may trigger every kind of reminiscence corruption points in Fluent Bit. The researchers tried out quite a lot of constructive and damaging integer values, specifically, to efficiently trigger errors for which the service would crash and leak doubtlessly delicate information.

Attackers may additionally doubtlessly use this identical trick to realize RCE capabilities in a focused surroundings. Nonetheless, Tenable famous, growing such an exploit would require a great deal of effort, being custom-made to the goal’s specific working system and structure.

What to Do About It

The bug exists in Fluent Bit variations 2.0.7 via 3.0.3. It is being tracked beneath CVE-2024-4323, and various sites have assigned it “vital” CVSS scores of over 9.5 out of 10. After it was reported on April 30, Fluent Bit’s maintainers updated the service to correctly validate information sorts in that problematic endpoint’s enter subject. The repair was utilized to the challenge’s foremost department on GitHub on Could 15.

Organizations with Fluent Bit deployed in their very own infrastructure and environments are suggested to replace as quickly as potential. Alternatively, Tenable suggests, directors can overview any configurations related to Fluent Bit’s monitoring API to make sure that solely licensed customers and companies can question it – and even no customers or companies in any respect.

See also  Equinix signs new wind PPA in Sweden with Neoen

Source link

Contents
The Linguistic Lumberjack ImpactWhat to Do About It
TAGGED: Bug, cloud, Critical, data, DoS, Leaks, Major, platforms, RCE
Share This Article
Twitter Email Copy Link Print
Previous Article Top 5 Data Center Stories, Week of May 2nd Top 5 Data Center Stories, Week of May 2nd
Next Article Microsoft and OpenAI say hackers are using ChatGPT to improve cyberattacks A cyberattack reportedly disabled over 600,000 US routers last year
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

Resynergi Raises $18M in Series B Extension

Resynergi, a Rohnert Park, CA-based modular superior plastic recycling expertise firm, raised $18M in Collection…

February 23, 2025

Gendo Raises £4.3M in Seed Funding

Gendo, a London, UK-based supplier of an AI platform for architects and designers, raised £4.3M…

November 17, 2024

Why we must rethink aspects of the famous Turing Test

Following Alan Turing’s seventieth anniversary, former Cambridge College pc science lecturer and software program CEO…

June 10, 2024

Accenture: AI’s True Potential Lies in Trust-Driven Technology Strategies

Accenture’s newest ‘Expertise Imaginative and prescient 2025’ report underscores a transformative period for companies as…

January 8, 2025

AI Drives New Era of Data Center Architecture

On the DCN Information Desk throughout Information Heart World 2025, SemiAnalysis expertise analyst Jeremie Eliahou…

May 16, 2025

You Might Also Like

Alerify and Zadara launch NVIDIA-powered sovereign AI cloud in Pennsylvania
Edge Computing

Alerify and Zadara launch NVIDIA-powered sovereign AI cloud in Pennsylvania

By saad
The evolution of Europe's data centre landscape: growth, challenges and sustainability
Power & Cooling

The evolution of Europe’s data centre landscape: growth, challenges and sustainability

By saad
Shutterstock Germany Only - News - Intel Factory Germany September 2024
Global Market

Intel sets sights on data center GPUs amid AI-driven infrastructure shifts

By saad
SpaceX
Global Market

Musk’s million data centers in space won’t fly, say experts

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.