Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rp46-r563-jrc7

Опубликовано: 13 фев. 2026
Источник: github
Github: Прошло ревью
CVSS4: 6.9

Описание

Apache Avro Java SDK is Vulnerable to Code Injection

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas.

This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0.

Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue.

Пакеты

Наименование

org.apache.avro:avro-compiler

maven
Затронутые версииВерсия исправления

= 1.12.0

1.12.1

Наименование

org.apache.avro:avro-compiler

maven
Затронутые версииВерсия исправления

< 1.11.5

1.11.5

EPSS

Процентиль: 46%
0.00602
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 5.6
redhat
6 месяцев назад

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue.

CVSS3: 7.3
nvd
6 месяцев назад

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue.

EPSS

Процентиль: 46%
0.00602
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-94