Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-39410

Опубликовано: 29 сент. 2023
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue.

A flaw was found in apache-avro. When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints, leading to an out-of-memory error and a denial of service on the system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2avroNot affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch6-rhel8Not affected
Red Hat build of Apache Camel for Spring Boot 3avroWill not fix
Red Hat build of Apicurio Registry 2avroAffected
Red Hat build of Debezium 2avroWill not fix
Red Hat Data Grid 8avroNot affected
Red Hat Enterprise Linux 8log4j:2/log4jNot affected
Red Hat Enterprise Linux 9log4jNot affected
Red Hat Integration Camel K 1avroNot affected
Red Hat Integration Camel Quarkus 2avroAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=2242521apache-avro: Apache Avro Java SDK: Memory when deserializing untrusted data in Avro Java SDK

EPSS

Процентиль: 19%
0.00061
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 2 лет назад

When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue.

CVSS3: 7.5
github
больше 2 лет назад

Apache Avro Java SDK vulnerable to Improper Input Validation

CVSS3: 7.5
fstec
больше 2 лет назад

Уязвимость библиотеки сериализации данных Apache Avro, связанная с недостатками механизма десериализации, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 19%
0.00061
Низкий

7.5 High

CVSS3

Уязвимость CVE-2023-39410