DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2024-47561

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-47561

CGA ID

CGA-jwf5-xmv5-8v4w

Severity

9.8

Critical

CVSS V3

Summary

Apache Avro Java SDK: Arbitrary Code Execution when reading Avro Data (Java SDK)

Description

Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code. Users are recommended to upgrade to version 1.11.4 or 1.12.0, which fix this issue.

References

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images