Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code. Users are recommended to upgrade to version 1.11.4 or 1.12.0, which fix this issue.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://lists.apache.org/thread/c2v7mhqnmq0jmbwxqq3r5jbj1xg43h5x | mailing list vendor advisory |
http://www.openwall.com/lists/oss-security/2024/10/03/1 | mailing list third party advisory |
https://security.netapp.com/advisory/ntap-20241011-0003/ | third party advisory |