Severity: critical

Affected versions:

- Apache Avro Java SDK before 1.11.4

Description:

Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions 
allows bad actors to execute arbitrary code.
Users are recommended to upgrade to version 1.11.4  or 1.12.0, which fix this 
issue.

Credit:

Kostya Kortchinsky, from the Databricks Security Team (finder)

References:

https://avro.apache.org/
https://www.cve.org/CVERecord?id=CVE-2024-47561

Reply via email to