treasuredata kayıtları
treasuredata üreticisine ait 19 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %5,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-476 NULL Pointer Dereference4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-787 Out-of-bounds Write2
- CWE-400 Uncontrolled Resource Consumption2
- CWE-306 Missing Authentication for Critical Function1
- CWE-415 Double Free1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
19 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
47Planlayın | CVE-2024-4323Kavram kanıtı | Fluent Bit Memory Corruption Vulnerabilitytreasuredata · fluent bit · CWE-122 | Kritik9,8 | — | %27,2 | 20 May 2024 |
40Planlayın | CVE-2021-36088İstismar yok | Fluent Bit (aka fluent-bit) 1.7.0 through 1.7.4 has a double free in flb_free (called from flb_parser_json_do and flb_parser_do).treasuredata · fluent bit · CWE-415 | Kritik9,8 | — | %2,4 | 30 Haz 2021 |
36İzleyin | CVE-2025-12977İstismar yok | Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to sanitize tag_key inputs.treasuredata · fluent bit · CWE-1287 | Kritik9,1 | — | %0,7 | 24 Kas 2025 |
35İzleyin | CVE-2025-12970İstismar yok | The extract_name function in Fluent Bit in_docker input plugin copies container names into a fixed size stack buffer without validating lengtreasuredata · fluent bit · CWE-120 | Yüksek8,8 | — | %1,0 | 24 Kas 2025 |
31İzleyin | CVE-2021-27186İstismar yok | Fluent Bit 1.6.10 has a NULL pointer dereference when an flb_malloc return value is not validated by flb_avro.c or http_server/api/v1/metrictreasuredata · fluent bit · CWE-476 | Yüksek7,5 | — | %2,0 | 10 Şub 2021 |
31İzleyin | CVE-2020-35963İstismar yok | flb_gzip_compress in flb_gzip.c in Fluent Bit before 1.6.4 has an out-of-bounds write because it does not use the correct calculation of thetreasuredata · fluent bit · CWE-787 | Yüksek7,8 | — | %1,3 | 3 Oca 2021 |
31İzleyin | CVE-2021-46879İstismar yok | An issue was discovered in Treasure Data Fluent Bit 1.7.1, a wrong variable is used to get the msgpack data resulting in a heap overflow in treasuredata · fluent bit · CWE-787 | Yüksek7,8 | — | %0,4 | 11 Nis 2023 |
31İzleyin | CVE-2021-46878İstismar yok | An issue was discovered in Treasure Data Fluent Bit 1.7.1, erroneous parsing in flb_pack_msgpack_to_json_format leads to type confusion bug treasuredata · fluent bit · CWE-843 | Yüksek7,8 | — | %0,4 | 11 Nis 2023 |
30İzleyin | CVE-2024-25125İstismar yok | Absolute path traversal vulnerability in digdag servertreasuredata · digdag · CWE-22 | Orta5,3 | — | %29,6 | 13 Şub 2024 |
30İzleyin | CVE-2019-9749İstismar yok | An issue was discovered in the MQTT input plugin in Fluent Bit through 1.0.4.treasuredata · fluent bit · CWE-681 | Yüksek7,5 | — | %1,7 | 13 Mar 2019 |
30İzleyin | CVE-2024-50609İstismar yok | An issue was discovered in Fluent Bit 3.1.9.treasuredata · fluent bit · CWE-476 | Yüksek7,5 | — | %1,1 | 18 Şub 2025 |
30İzleyin | CVE-2024-50608İstismar yok | An issue was discovered in Fluent Bit 3.1.9.treasuredata · fluent bit · CWE-476 | Yüksek7,5 | — | %1,1 | 18 Şub 2025 |
30İzleyin | CVE-2024-23722Kavram kanıtı | In Fluent Bit 2.1.8 through 2.2.1, a NULL pointer dereference can be caused via an invalid HTTP payload with the content type of x-www-form-treasuredata · fluent bit · CWE-476 | Yüksek7,5 | — | %0,9 | 26 Mar 2024 |
30İzleyin | CVE-2024-26455İstismar yok | fluent-bit 2.2.2 contains a Use-After-Free vulnerability in /fluent-bit/plugins/custom_calyptia/calyptia.c.treasuredata · fluent bit · CWE-416 | Yüksek7,5 | — | %0,7 | 26 Şub 2024 |
26İzleyin | CVE-2025-12969İstismar yok | Fluent Bit in_forward input plugin does not properly enforce the security.users authentication mechanism under certain configuration condititreasuredata · fluent bit · CWE-306 | Orta6,5 | — | %0,6 | 24 Kas 2025 |
22İzleyin | CVE-2025-29478İstismar yok | An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:165.treasuredata · fluent bit · CWE-400 | Orta5,5 | — | %0,2 | 7 Nis 2025 |
22İzleyin | CVE-2025-29477İstismar yok | An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the function consume_event.treasuredata · fluent bit · CWE-400 | Orta5,5 | — | %0,2 | 4 Nis 2025 |
21İzleyin | CVE-2025-12972İstismar yok | Fluent Bit out_file plugin does not properly sanitize tag values when deriving output file names.treasuredata · fluent bit · CWE-22 | Orta5,3 | — | %0,9 | 24 Kas 2025 |
21İzleyin | CVE-2025-12978İstismar yok | Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a flaw in the tag_key validation logic that fails to enforce exacttreasuredata · fluent bit · CWE-187 | Orta5,4 | — | %0,4 | 24 Kas 2025 |
- CVE-2024-432347Planlayın
Fluent Bit Memory Corruption Vulnerability
KritikCVSS 9,8Kavram kanıtıEPSS %27treasuredata · fluent bit20 May 2024
- CVE-2021-3608840Planlayın
Fluent Bit (aka fluent-bit) 1.7.0 through 1.7.4 has a double free in flb_free (called from flb_parser_json_do and flb_parser_do).
KritikCVSS 9,8İstismar yokEPSS %2treasuredata · fluent bit30 Haz 2021
- CVE-2025-1297736İzleyin
Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to sanitize tag_key inputs.
KritikCVSS 9,1İstismar yokEPSS %1treasuredata · fluent bit24 Kas 2025
- CVE-2025-1297035İzleyin
The extract_name function in Fluent Bit in_docker input plugin copies container names into a fixed size stack buffer without validating leng
YüksekCVSS 8,8İstismar yokEPSS %1treasuredata · fluent bit24 Kas 2025
- CVE-2021-2718631İzleyin
Fluent Bit 1.6.10 has a NULL pointer dereference when an flb_malloc return value is not validated by flb_avro.c or http_server/api/v1/metric
YüksekCVSS 7,5İstismar yokEPSS %2treasuredata · fluent bit10 Şub 2021
- CVE-2020-3596331İzleyin
flb_gzip_compress in flb_gzip.c in Fluent Bit before 1.6.4 has an out-of-bounds write because it does not use the correct calculation of the
YüksekCVSS 7,8İstismar yokEPSS %1treasuredata · fluent bit3 Oca 2021
- CVE-2021-4687931İzleyin
An issue was discovered in Treasure Data Fluent Bit 1.7.1, a wrong variable is used to get the msgpack data resulting in a heap overflow in
YüksekCVSS 7,8İstismar yokEPSS %0treasuredata · fluent bit11 Nis 2023
- CVE-2021-4687831İzleyin
An issue was discovered in Treasure Data Fluent Bit 1.7.1, erroneous parsing in flb_pack_msgpack_to_json_format leads to type confusion bug
YüksekCVSS 7,8İstismar yokEPSS %0treasuredata · fluent bit11 Nis 2023
- CVE-2024-2512530İzleyin
Absolute path traversal vulnerability in digdag server
OrtaCVSS 5,3İstismar yokEPSS %30treasuredata · digdag13 Şub 2024
- CVE-2019-974930İzleyin
An issue was discovered in the MQTT input plugin in Fluent Bit through 1.0.4.
YüksekCVSS 7,5İstismar yokEPSS %2treasuredata · fluent bit13 Mar 2019
- CVE-2024-5060930İzleyin
An issue was discovered in Fluent Bit 3.1.9.
YüksekCVSS 7,5İstismar yokEPSS %1treasuredata · fluent bit18 Şub 2025
- CVE-2024-5060830İzleyin
An issue was discovered in Fluent Bit 3.1.9.
YüksekCVSS 7,5İstismar yokEPSS %1treasuredata · fluent bit18 Şub 2025
- CVE-2024-2372230İzleyin
In Fluent Bit 2.1.8 through 2.2.1, a NULL pointer dereference can be caused via an invalid HTTP payload with the content type of x-www-form-
YüksekCVSS 7,5Kavram kanıtıEPSS %1treasuredata · fluent bit26 Mar 2024
- CVE-2024-2645530İzleyin
fluent-bit 2.2.2 contains a Use-After-Free vulnerability in /fluent-bit/plugins/custom_calyptia/calyptia.c.
YüksekCVSS 7,5İstismar yokEPSS %1treasuredata · fluent bit26 Şub 2024
- CVE-2025-1296926İzleyin
Fluent Bit in_forward input plugin does not properly enforce the security.users authentication mechanism under certain configuration conditi
OrtaCVSS 6,5İstismar yokEPSS %1treasuredata · fluent bit24 Kas 2025
- CVE-2025-2947822İzleyin
An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:165.
OrtaCVSS 5,5İstismar yokEPSS %0treasuredata · fluent bit7 Nis 2025
- CVE-2025-2947722İzleyin
An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the function consume_event.
OrtaCVSS 5,5İstismar yokEPSS %0treasuredata · fluent bit4 Nis 2025
- CVE-2025-1297221İzleyin
Fluent Bit out_file plugin does not properly sanitize tag values when deriving output file names.
OrtaCVSS 5,3İstismar yokEPSS %1treasuredata · fluent bit24 Kas 2025
- CVE-2025-1297821İzleyin
Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a flaw in the tag_key validation logic that fails to enforce exact
OrtaCVSS 5,4İstismar yokEPSS %0treasuredata · fluent bit24 Kas 2025