oss-sec mailing list archives

CVE-2021-43045: Apache Avro: Possible DOS vulnerabilities in C# Avro SDK


From: Ryan Skraba <rskraba () apache org>
Date: Thu, 06 Jan 2022 17:48:38 +0000

Description:

A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing 
a denial-of-service attack.  This issue affects .NET applications using Apache Avro version 1.10.2 and prior versions.  
Users should update to version 1.11.0 which addresses this issue.

This issue is being tracked as AVRO-3225,AVRO-3226

Credit:

Apache Avro would like to thank Philip Sanetra for reporting this issue.


Current thread: