Possible DOS vulnerabilities in C# Avro SDK
CVE-2021-43045

7.5HIGH

Key Information:

Vendor
Apache
Vendor
CVE Published:
6 January 2022

Summary

A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a denial-of-service attack. This issue affects .NET applications using Apache Avro version 1.10.2 and prior versions. Users should update to version 1.11.0 which addresses this issue.

Affected Version(s)

Apache Avro .NET Apache Avro <= 1.10.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Apache Avro would like to thank Philip Sanetra for reporting this issue.
.