Apache Avro Java SDK
cpe:2.3:a:apache:avro:*:*:*:*:*:*:*
- <= 1.11.4
- 1.12.0
A code injection vulnerability has been identified in the Apache Avro Java SDK, specifically in versions through 1.11.4 and 1.12.0. This vulnerability arises from improper control of code generation when creating specific records from untrusted Avro schemas.
Exploitation of this vulnerability allows for code injection through the manipulation of untrusted Avro schemas, potentially leading to arbitrary code execution in the context of the application using the Avro Java SDK.
Users are advised to upgrade to Apache Avro Java SDK versions 1.12.1 or 1.11.5, both of which address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.