Skip to content

🔐 CVE-2024-47561: org.apache.avro:avro:jar:1.11.3:compile #56

@github-actions

Description

@github-actions

Summary

Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code.
Users are recommended to upgrade to version 1.11.4  or 1.12.0, which fix this issue.

CVE: CVE-2024-47561
CWE: CWE-502

References

Metadata

Metadata

Assignees

Labels

securitySecurity related change

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions