Skip to content

Commit

Permalink
Browse files Browse the repository at this point in the history
  • Loading branch information
advisory-database[bot] committed Oct 3, 2023
1 parent 17a7452 commit 4a0f30a
Showing 1 changed file with 8 additions and 4 deletions.
Original file line number Diff line number Diff line change
@@ -1,15 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rhrv-645h-fjfh",
"modified": "2023-09-29T22:06:14Z",
"modified": "2023-10-03T21:51:29Z",
"published": "2023-09-29T18:30:22Z",
"aliases": [
"CVE-2023-39410"
],
"summary": "Apache Avro Java SDK vulnerable to Improper Input Validation",
"details": "When deserializing untrusted or corrupted data, it is possible for a reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system.\n\nThis issue affects Java applications using Apache Avro Java SDK up to and including 1.11.2. Users should update to apache-avro version 1.11.3 which addresses this issue.\n\n",
"severity": [

{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
{
Expand Down Expand Up @@ -61,9 +64,10 @@
],
"database_specific": {
"cwe_ids": [
"CWE-20"
"CWE-20",
"CWE-502"
],
"severity": "MODERATE",
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2023-09-29T22:06:14Z",
"nvd_published_at": null
Expand Down

0 comments on commit 4a0f30a

Please sign in to comment.