Записи treasuredata
19 опубликованных записей вендора treasuredata.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 21,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-476 NULL Pointer Dereference4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-787 Out-of-bounds Write2
- CWE-400 Uncontrolled Resource Consumption2
- CWE-306 Missing Authentication for Critical Function1
- CWE-415 Double Free1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
19 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
47В плане | CVE-2024-4323Proof of concept | Fluent Bit Memory Corruption Vulnerabilitytreasuredata · fluent bit · CWE-122 | Критическая9,8 | — | 27,2 % | 20 мая 2024 г. |
40В плане | CVE-2021-36088Эксплойта нет | Fluent Bit (aka fluent-bit) 1.7.0 through 1.7.4 has a double free in flb_free (called from flb_parser_json_do and flb_parser_do).treasuredata · fluent bit · CWE-415 | Критическая9,8 | — | 2,4 % | 30 июн. 2021 г. |
36Наблюдать | CVE-2025-12977Эксплойта нет | Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to sanitize tag_key inputs.treasuredata · fluent bit · CWE-1287 | Критическая9,1 | — | 0,7 % | 24 нояб. 2025 г. |
35Наблюдать | CVE-2025-12970Эксплойта нет | The extract_name function in Fluent Bit in_docker input plugin copies container names into a fixed size stack buffer without validating lengtreasuredata · fluent bit · CWE-120 | Высокая8,8 | — | 1,0 % | 24 нояб. 2025 г. |
31Наблюдать | CVE-2021-27186Эксплойта нет | Fluent Bit 1.6.10 has a NULL pointer dereference when an flb_malloc return value is not validated by flb_avro.c or http_server/api/v1/metrictreasuredata · fluent bit · CWE-476 | Высокая7,5 | — | 2,0 % | 10 февр. 2021 г. |
31Наблюдать | CVE-2020-35963Эксплойта нет | flb_gzip_compress in flb_gzip.c in Fluent Bit before 1.6.4 has an out-of-bounds write because it does not use the correct calculation of thetreasuredata · fluent bit · CWE-787 | Высокая7,8 | — | 1,3 % | 3 янв. 2021 г. |
31Наблюдать | CVE-2021-46879Эксплойта нет | An issue was discovered in Treasure Data Fluent Bit 1.7.1, a wrong variable is used to get the msgpack data resulting in a heap overflow in treasuredata · fluent bit · CWE-787 | Высокая7,8 | — | 0,4 % | 11 апр. 2023 г. |
31Наблюдать | CVE-2021-46878Эксплойта нет | An issue was discovered in Treasure Data Fluent Bit 1.7.1, erroneous parsing in flb_pack_msgpack_to_json_format leads to type confusion bug treasuredata · fluent bit · CWE-843 | Высокая7,8 | — | 0,4 % | 11 апр. 2023 г. |
30Наблюдать | CVE-2024-25125Эксплойта нет | Absolute path traversal vulnerability in digdag servertreasuredata · digdag · CWE-22 | Средняя5,3 | — | 29,6 % | 13 февр. 2024 г. |
30Наблюдать | CVE-2019-9749Эксплойта нет | An issue was discovered in the MQTT input plugin in Fluent Bit through 1.0.4.treasuredata · fluent bit · CWE-681 | Высокая7,5 | — | 1,7 % | 13 мар. 2019 г. |
30Наблюдать | CVE-2024-50609Эксплойта нет | An issue was discovered in Fluent Bit 3.1.9.treasuredata · fluent bit · CWE-476 | Высокая7,5 | — | 1,1 % | 18 февр. 2025 г. |
30Наблюдать | CVE-2024-50608Эксплойта нет | An issue was discovered in Fluent Bit 3.1.9.treasuredata · fluent bit · CWE-476 | Высокая7,5 | — | 1,1 % | 18 февр. 2025 г. |
30Наблюдать | CVE-2024-23722Proof of concept | In Fluent Bit 2.1.8 through 2.2.1, a NULL pointer dereference can be caused via an invalid HTTP payload with the content type of x-www-form-treasuredata · fluent bit · CWE-476 | Высокая7,5 | — | 0,9 % | 26 мар. 2024 г. |
30Наблюдать | CVE-2024-26455Эксплойта нет | fluent-bit 2.2.2 contains a Use-After-Free vulnerability in /fluent-bit/plugins/custom_calyptia/calyptia.c.treasuredata · fluent bit · CWE-416 | Высокая7,5 | — | 0,7 % | 26 февр. 2024 г. |
26Наблюдать | CVE-2025-12969Эксплойта нет | Fluent Bit in_forward input plugin does not properly enforce the security.users authentication mechanism under certain configuration condititreasuredata · fluent bit · CWE-306 | Средняя6,5 | — | 0,6 % | 24 нояб. 2025 г. |
22Наблюдать | CVE-2025-29478Эксплойта нет | An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:165.treasuredata · fluent bit · CWE-400 | Средняя5,5 | — | 0,2 % | 7 апр. 2025 г. |
22Наблюдать | CVE-2025-29477Эксплойта нет | An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the function consume_event.treasuredata · fluent bit · CWE-400 | Средняя5,5 | — | 0,2 % | 4 апр. 2025 г. |
21Наблюдать | CVE-2025-12972Эксплойта нет | Fluent Bit out_file plugin does not properly sanitize tag values when deriving output file names.treasuredata · fluent bit · CWE-22 | Средняя5,3 | — | 0,9 % | 24 нояб. 2025 г. |
21Наблюдать | CVE-2025-12978Эксплойта нет | Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a flaw in the tag_key validation logic that fails to enforce exacttreasuredata · fluent bit · CWE-187 | Средняя5,4 | — | 0,4 % | 24 нояб. 2025 г. |
- CVE-2024-432347В плане
Fluent Bit Memory Corruption Vulnerability
КритическаяCVSS 9,8Proof of conceptEPSS 27 %treasuredata · fluent bit20 мая 2024 г.
- CVE-2021-3608840В плане
Fluent Bit (aka fluent-bit) 1.7.0 through 1.7.4 has a double free in flb_free (called from flb_parser_json_do and flb_parser_do).
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %treasuredata · fluent bit30 июн. 2021 г.
- CVE-2025-1297736Наблюдать
Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to sanitize tag_key inputs.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %treasuredata · fluent bit24 нояб. 2025 г.
- CVE-2025-1297035Наблюдать
The extract_name function in Fluent Bit in_docker input plugin copies container names into a fixed size stack buffer without validating leng
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %treasuredata · fluent bit24 нояб. 2025 г.
- CVE-2021-2718631Наблюдать
Fluent Bit 1.6.10 has a NULL pointer dereference when an flb_malloc return value is not validated by flb_avro.c or http_server/api/v1/metric
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %treasuredata · fluent bit10 февр. 2021 г.
- CVE-2020-3596331Наблюдать
flb_gzip_compress in flb_gzip.c in Fluent Bit before 1.6.4 has an out-of-bounds write because it does not use the correct calculation of the
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %treasuredata · fluent bit3 янв. 2021 г.
- CVE-2021-4687931Наблюдать
An issue was discovered in Treasure Data Fluent Bit 1.7.1, a wrong variable is used to get the msgpack data resulting in a heap overflow in
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %treasuredata · fluent bit11 апр. 2023 г.
- CVE-2021-4687831Наблюдать
An issue was discovered in Treasure Data Fluent Bit 1.7.1, erroneous parsing in flb_pack_msgpack_to_json_format leads to type confusion bug
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %treasuredata · fluent bit11 апр. 2023 г.
- CVE-2024-2512530Наблюдать
Absolute path traversal vulnerability in digdag server
СредняяCVSS 5,3Эксплойта нетEPSS 30 %treasuredata · digdag13 февр. 2024 г.
- CVE-2019-974930Наблюдать
An issue was discovered in the MQTT input plugin in Fluent Bit through 1.0.4.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %treasuredata · fluent bit13 мар. 2019 г.
- CVE-2024-5060930Наблюдать
An issue was discovered in Fluent Bit 3.1.9.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %treasuredata · fluent bit18 февр. 2025 г.
- CVE-2024-5060830Наблюдать
An issue was discovered in Fluent Bit 3.1.9.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %treasuredata · fluent bit18 февр. 2025 г.
- CVE-2024-2372230Наблюдать
In Fluent Bit 2.1.8 through 2.2.1, a NULL pointer dereference can be caused via an invalid HTTP payload with the content type of x-www-form-
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %treasuredata · fluent bit26 мар. 2024 г.
- CVE-2024-2645530Наблюдать
fluent-bit 2.2.2 contains a Use-After-Free vulnerability in /fluent-bit/plugins/custom_calyptia/calyptia.c.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %treasuredata · fluent bit26 февр. 2024 г.
- CVE-2025-1296926Наблюдать
Fluent Bit in_forward input plugin does not properly enforce the security.users authentication mechanism under certain configuration conditi
СредняяCVSS 6,5Эксплойта нетEPSS 1 %treasuredata · fluent bit24 нояб. 2025 г.
- CVE-2025-2947822Наблюдать
An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:165.
СредняяCVSS 5,5Эксплойта нетEPSS 0 %treasuredata · fluent bit7 апр. 2025 г.
- CVE-2025-2947722Наблюдать
An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the function consume_event.
СредняяCVSS 5,5Эксплойта нетEPSS 0 %treasuredata · fluent bit4 апр. 2025 г.
- CVE-2025-1297221Наблюдать
Fluent Bit out_file plugin does not properly sanitize tag values when deriving output file names.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %treasuredata · fluent bit24 нояб. 2025 г.
- CVE-2025-1297821Наблюдать
Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a flaw in the tag_key validation logic that fails to enforce exact
СредняяCVSS 5,4Эксплойта нетEPSS 0 %treasuredata · fluent bit24 нояб. 2025 г.