Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-43045

Опубликовано: 06 янв. 2022
Источник: redhat
CVSS3: 7.5

Описание

A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a denial-of-service attack. This issue affects .NET applications using Apache Avro version 1.10.2 and prior versions. Users should update to version 1.11.0 which addresses this issue.

Отчет

CodeReady Studio is no longer supported and therefore this flaw will not be addressed in CodeReady Studio. Please see https://developers.redhat.com/articles/2022/04/18/announcement-red-hat-codeready-studio-reaches-end-life for more information.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat CodeReady Studio 12avroOut of support scope
Red Hat Fuse 7avroNot affected
Red Hat Integration Camel K 1avroNot affected
Red Hat Integration Service RegistryavroNot affected
Red Hat JBoss Data Grid 7avroNot affected
Red Hat JBoss Data Virtualization 6avroNot affected
Red Hat JBoss Enterprise Application Platform 6avroNot affected
Red Hat JBoss Enterprise Application Platform 7avroNot affected
Red Hat JBoss Enterprise Application Platform Expansion PackavroNot affected
Red Hat JBoss Fuse 6avroNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2042576apache-avro: allows attackers to allocate excessive resources potentially causing a DoS

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 4 лет назад

A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a denial-of-service attack. This issue affects .NET applications using Apache Avro version 1.10.2 and prior versions. Users should update to version 1.11.0 which addresses this issue.

CVSS3: 7.5
github
около 4 лет назад

Allocation of Resources Without Limits or Throttling in Apache Avro

7.5 High

CVSS3