Apache Avro Java SDK: Memory when deserializing untrusted data in Avro Java SDK
Vulnerability Description
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-39410
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Adam Korczynski at ADA Logics Ltd
References
More from Apache Software Foundation
View All →Affected Vendor
Apache Software Foundation
View all reports →