Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1yaHJ2LTY0NWgtZmpmaM4AA2Jb
Apache Avro Java SDK vulnerable to Improper Input Validation
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system.
This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue.
Permalink: https://github.com/advisories/GHSA-rhrv-645h-fjfhJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1yaHJ2LTY0NWgtZmpmaM4AA2Jb
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: about 1 year ago
Updated: 6 months ago
CVSS Score: 7.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Percentage: 0.00668
EPSS Percentile: 0.80161
Identifiers: GHSA-rhrv-645h-fjfh, CVE-2023-39410
References:
- https://nvd.nist.gov/vuln/detail/CVE-2023-39410
- https://lists.apache.org/thread/q142wj99cwdd0jo5lvdoxzoymlqyjdds
- http://www.openwall.com/lists/oss-security/2023/09/29/6
- https://github.com/apache/avro/commit/a12a7e44ddbe060c3dc731863cad5c15f9267828
- https://github.com/pypa/advisory-database/tree/main/vulns/avro/PYSEC-2023-188.yaml
- https://www.openwall.com/lists/oss-security/2023/09/29/6
- https://security.netapp.com/advisory/ntap-20240621-0006
- https://github.com/advisories/GHSA-rhrv-645h-fjfh
Blast Radius: 54.2
Affected Packages
pypi:avro
Dependent packages: 59Dependent repositories: 1,066
Downloads: 9,459,670 last month
Affected Version Ranges: >= 0, < 1.11.3
Fixed in: 1.11.3
All affected versions: 1.3.3, 1.4.1, 1.5.0, 1.5.1, 1.5.2, 1.5.3, 1.5.4, 1.6.0, 1.6.1, 1.6.2, 1.6.3, 1.7.0, 1.7.1, 1.7.2, 1.7.3, 1.7.4, 1.7.5, 1.7.6, 1.7.7, 1.8.0, 1.8.1, 1.8.2, 1.9.0, 1.9.1, 1.9.2, 1.10.0, 1.10.1, 1.10.2, 1.11.0, 1.11.1, 1.11.2
All unaffected versions: 1.11.3, 1.12.0
maven:org.apache.avro:avro
Dependent packages: 1,964Dependent repositories: 15,858
Downloads:
Affected Version Ranges: < 1.11.3
Fixed in: 1.11.3
All affected versions: 1.4.0, 1.4.1, 1.5.0, 1.5.1, 1.5.2, 1.5.3, 1.5.4, 1.6.0, 1.6.1, 1.6.2, 1.6.3, 1.7.0, 1.7.1, 1.7.2, 1.7.3, 1.7.4, 1.7.5, 1.7.6, 1.7.7, 1.8.0, 1.8.1, 1.8.2, 1.9.0, 1.9.1, 1.9.2, 1.10.0, 1.10.1, 1.10.2, 1.11.0, 1.11.1, 1.11.2
All unaffected versions: 1.11.3, 1.11.4, 1.12.0