Vulnerabilities > CVE-2021-36088 - Double Free vulnerability in Treasuredata Fluent BIT 1.7.0/1.7.1

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
treasuredata
CWE-415
critical

Summary

Fluent Bit (aka fluent-bit) 1.7.0 through 1.7.4 has a double free in flb_free (called from flb_parser_json_do and flb_parser_do).

Vulnerable Configurations

Part Description Count
Application
Treasuredata
6

Common Weakness Enumeration (CWE)