All vulnerabilities
CVE-2023-39410
Apache Avro Java SDK vulnerable to Improper Input Validation
Description
When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system.
This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue.
Patch Available
Fix available through Seal Security.
No upgrade required, protect your application instantly.
Fix without upgrading
Score
Severity
Ecosystem
Java
Publish Date
September 29, 2023
Modified Date
November 7, 2023
Score Vector
Affected Versions

