CVE-2023-39410

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
29/09/2023
Last modified:
13/02/2025

Description

When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system.<br /> <br /> This issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:avro:*:*:*:*:*:-:*:* 1.11.3 (excluding)