Out-of-bounds Write The advisory has been revoked - it doesn't affect any version of package fluent-bit-3.0  (opens in a new tab)


Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
28.31% (98th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CHAINGUARDLATEST-FLUENTBIT30-6966888
  • published21 May 2024
  • disclosed20 May 2024

Introduced: 20 May 2024

CVE-2024-4323  (opens in a new tab)
CWE-787  (opens in a new tab)

Amendment

The Chainguard security team deemed this advisory irrelevant for Chainguard:latest.

NVD Description

Note: Versions mentioned in the description apply only to the upstream fluent-bit-3.0 package and not the fluent-bit-3.0 package as distributed by Chainguard.

A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s parsing of trace requests and may result in denial of service conditions, information disclosure, or remote code execution.