CVE-2021-46879: High severity fluent bit by treasure data vulnerability
An issue was discovered in Treasure Data Fluent Bit 1.7.1, a wrong variable is used to get the msgpack data resulting in a heap overflow in flbmsgpackgelfvalueext. An attacker can craft a malicious file and tick the victim to open the file with the software, triggering a heap overflow and execute arbitrary code on the target system.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-46879?
CVE-2021-46879 is classified as a high severity vulnerability due to its potential to cause a heap overflow.
How do I fix CVE-2021-46879?
To mitigate CVE-2021-46879, upgrade Fluent Bit to version 1.7.3 or later.
What software is affected by CVE-2021-46879?
CVE-2021-46879 specifically affects Fluent Bit version 1.7.1.
What type of vulnerability is CVE-2021-46879?
CVE-2021-46879 is a heap overflow vulnerability related to improper handling of msgpack data.
Can CVE-2021-46879 be exploited remotely?
Yes, CVE-2021-46879 can be exploited if an attacker tricks a victim into opening a crafted file.