Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code. Users are recommended to upgrade to version 1.11.4 or 1.12.0, which fix this issue.
The vulnerability results from unsafe deserialization (CWE-502) in the schema parsing mechanism of Apache Avro Java SDK. An attacker can provide a crafted schema whose processing by the vulnerable library leads to arbitrary code execution in the application context. The attack can be performed remotely without authentication.
An attacker can execute arbitrary code on a server or in an application processing an Avro schema, which may lead to complete system compromise, data theft, or data modification.
Apache Avro Java SDK should be updated to version 1.11.4 or 1.12.0, which eliminate the vulnerability. Users of NetApp products (Active IQ Unified Manager, Brocade SAN Navigator) should apply patches available from the vendor according to references (advisory ntap-20241011-0003).
Apache Avro Java SDK version 1.11.3 and earlier. The vulnerability also affects NetApp products: Active IQ Unified Manager and Brocade SAN Navigator, which use this library.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XApache Avro
APPApache< 1.11.4Netapp Active Iq Unified Manager
APPNetappall versionsNetapp Brocade San Navigator
APPNetappall versions
Related vulnerabilities
Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup
Buffer overflow w GNOME GLib — błąd off-by-one w obsłudze SOCKS4
Heap buffer overflow w libcurl podczas handshake z proxy SOCKS5
Stack-buffer-overflow w bibliotece json-c (funkcja parseit)
curl: pominięcie ochrony HSTS przy seryjnym pobieraniu wielu URL-i