7.5
CVSSv3

CVE-2023-39410

Published: 29/09/2023 Updated: 06/10/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache avro

Vendor Advisories

Synopsis Important: Red Hat JBoss Enterprise Application Platform 7414 on RHEL 9 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update is now available for Red Hat JBoss Enterprise Application Platfo ...
Synopsis Critical: Red Hat Fuse 7121 release and security update Type/Severity Security Advisory: Critical Topic A minor version update (from 712 to 7121) is now available for Red Hat Fuse The purpose of this text-only errata is to inform you about the security issues fixed in this releaseRed Hat Product Security has rated this update ...
概要 Important: Red Hat Build of Apache Camel for Quarkus 320 release (RHBQ 329Final) タイプ/重大度 Security Advisory: Important トピック Red Hat Build of Apache Camel for Quarkus 320 is now available (updates to RHBQ 329Final) The purpose of this text-only errata is to inform you about the enhancements that improve yo ...
Synopsis Important: Red Hat build of Quarkus 2139 release and security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat build of QuarkusRed Hat Product Security has rated this update as having a security impact ofModerate A Common Vulnerability Scoring System (CVSS) base score, which gives ade ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 7414 on RHEL 8 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update is now available for Red Hat JBoss Enterprise Application Platfo ...
概要 Important: Red Hat build of Quarkus 329 release and security update タイプ/重大度 Security Advisory: Important トピック A new release of the Red Hat build of Quarkus is now available This new release comes packed with a host of enhancements, bug fixes, and security fixesRed Hat Product Security has rated this update as ha ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 7414 on RHEL 7 security update Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update is now available for Red Hat JBoss Enterprise Application Platfo ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 7414 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat JBoss Enterprise Application Platform 74Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring Syste ...