Friday, 10 Apr 2026
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Cloud Computing > Critical Bug Allows DoS, RCE, Data Leaks in All Major Cloud Platforms | DCN
Cloud Computing

Critical Bug Allows DoS, RCE, Data Leaks in All Major Cloud Platforms | DCN

Last updated: May 22, 2024 5:31 pm
Published May 22, 2024
Share
Cloud security icon
SHARE

Researchers have found a extreme reminiscence corruption vulnerability inside a cloud logging utility used throughout main cloud platforms.

The service, Fluent Bit, is an open supply device for accumulating, processing, and forwarding logs and different kinds of software knowledge. It is one of many extra common items of software program on the market, with greater than three billion downloads as of 2022, and a brand new 10 million or so deployments with every passing day. It is utilized by main organizations resembling VMware, Cisco, Adobe, Walmart, and LinkedIn, and almost each main cloud service supplier, together with AWS, Microsoft, and Google Cloud.

Associated: Securing Edge Knowledge Facilities: Challenges and Options

The difficulty with Fluent Bit, dubbed “Linguistic Lumberjack” in a new report from Tenable, lies in how the service’s embedded HTTP server parses hint requests. Manipulated in a technique or one other, it will probably trigger denial of service (DoS), knowledge leakage, or distant code execution (RCE) in a cloud setting.

“Everybody will get hyped a couple of vulnerability in Azure, AWS, GCP, however no person’s actually trying on the applied sciences that make up all of those main cloud providers – frequent, core items of software program that now have an effect on each main cloud supplier,” says Jimi Sebree, senior employees analysis engineer with Tenable. “It’s good to be searching for software safety bombs and like elements of the providers, not simply the providers themselves.”

The Linguistic Lumberjack Impact

Associated: A Information to the High Knowledge Heart Safety Certifications

Tenable researchers initially have been trying into a wholly separate safety concern in an undisclosed cloud service once they realized one thing sudden was occurring. From the place they have been sitting, it appeared they have been capable of entry a variety of the cloud service supplier’s (CSP) personal inner metrics and logging endpoints. Amongst these have been cases of Fluent Bit.

See also  US Manufacturing Needs an ‘AI Backbone’ to Compete | DCN

This cross-tenant knowledge leakage got here from endpoints in Fluent Bit’s monitoring software programming interface (API), designed to permit customers to question and monitor its inner knowledge. After some testing, although, a little bit of leaky knowledge turned out to be solely the introduction to a deeper drawback.

For a specific endpoint – /api/v1/traces – the kinds of knowledge handed as enter names weren’t correctly validated previous to being parsed by this system. So by passing non-string values, an attacker may trigger all types of reminiscence corruption points in Fluent Bit. The researchers tried out quite a lot of constructive and adverse integer values, particularly, to efficiently trigger errors for which the service would crash and leak probably delicate knowledge.

Attackers may additionally probably use this similar trick to realize RCE capabilities in a focused setting. Nevertheless, Tenable famous, creating such an exploit would require a great deal of effort, being custom-made to the goal’s explicit working system and structure.

What to Do About It

The bug exists in Fluent Bit variations 2.0.7 by 3.0.3. It is being tracked underneath CVE-2024-4323, and various sites have assigned it “essential” CVSS scores of over 9.5 out of 10. After it was reported on April 30, Fluent Bit’s maintainers updated the service to correctly validate knowledge sorts in that problematic endpoint’s enter area. The repair was utilized to the venture’s primary department on GitHub on Might 15.

Organizations with Fluent Bit deployed in their very own infrastructure and environments are suggested to replace as quickly as attainable. Alternatively, Tenable suggests, directors can overview any configurations related to Fluent Bit’s monitoring API to make sure that solely licensed customers and providers can question it – and even no customers or providers in any respect.

See also  Which one is right for you?

Source link

Contents
The Linguistic Lumberjack ImpactWhat to Do About It
TAGGED: Bug, cloud, Critical, data, DCN, DoS, Leaks, Major, platforms, RCE
Share This Article
Twitter Email Copy Link Print
Previous Article Microsoft Copilot AI Image Upgrade Deucalion Model Microsoft Partners with UAE-Based G42 to Invest $1 Billion in Kenya Data Center
Next Article How to avoid becoming a stranded asset How to avoid becoming a stranded asset
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

IonQ Unveils Advanced Quantum Error Correction Method

IonQ (NYSE: IONQ), a worldwide supplier of quantum computing applied sciences, has unveiled a brand…

August 8, 2024

Nokia Unveils 50G PON for Quantum-Secure Enterprise Connectivity

Nokia has launched its 50G Passive Optical Community (PON) resolution, a significant step ahead in…

October 9, 2025

Ex-OpenAI CTO Mira Murati unveils Thinking Machines: A startup focused on multimodality, human-AI collaboration

Be a part of our each day and weekly newsletters for the most recent updates…

February 19, 2025

Litecoin vs Bitcoin — Common Grounds and Distinct Differences

Bitcoin is the indeniable king of the crypto market, but it surely’s not the one…

February 18, 2024

Hitachi Invests $1B in U.S. Grid Infrastructure to Power AI Data Centers

Hitachi Power, a subsidiary of Hitachi, has introduced greater than $1 billion in new U.S.…

September 7, 2025

You Might Also Like

NTT DATA reveals next-gen Keihanna OSK11 data centre in Kyoto
Power & Cooling

NTT DATA reveals next-gen Keihanna OSK11 data centre in Kyoto

By saad
EMEA data centre vacancy hits record low as AI demand outpaces supply
Global Market

EMEA data centre vacancy hits record low as AI demand outpaces supply

By saad
CoreWeave secures AI cloud capacity deal with Meta through 2032
Design

CoreWeave secures AI cloud capacity deal with Meta through 2032

By saad
Zoho confirms launch plans for UK data centre
Global Market

Zoho confirms launch plans for UK data centre

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.