CVE-2025-29477: Medium severity Fluent Bit Fluent Bit vulnerability
Published Apr 4, 2025
·Updated
An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the function consumeevent.
Affected Software
9 affected components
Fluent Bit Fluent Bit
Microsoft azl3 fluent-bit 3.1.9-4
Microsoft azl3 fluent-bit 3.1.9-5
Microsoft azl3 fluent-bit 3.1.9-6
Microsoft cbl2 fluent-bit 3.0.6-6
Microsoft cbl2 fluent-bit 3.0.6-4
Microsoft cbl2 fluent-bit 3.0.6-3
Microsoft azl3 fluent-bit 3.1.10-2
Treasuredata Fluent Bit
Event History
Apr 4, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Sep 3, 2025
Data Sourced
via Microsoft·11:34 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·11:34 PM
SeverityAffected Software
Updated
via Microsoft·11:34 PM
Affected Software
Updated
via Microsoft·11:34 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-29477?
The severity of CVE-2025-29477 is classified as high due to its potential for causing denial of service.
2
How do I fix CVE-2025-29477?
To fix CVE-2025-29477, update Fluent Bit to the latest version that has addressed this vulnerability.
3
Who is affected by CVE-2025-29477?
CVE-2025-29477 affects users of Fluent Bit version 3.7.2 and potentially earlier versions.
4
What are the potential impacts of CVE-2025-29477?
The potential impacts of CVE-2025-29477 include denial of service, causing the application to crash or become unresponsive.
5
Is CVE-2025-29477 a local or remote vulnerability?
CVE-2025-29477 is a local vulnerability, meaning it requires local access to exploit.