The Apache Avro Java Software Development Kit (SDK) includes a significant security hole that, if successfully exploited, could grant arbitrary code execution on vulnerable instances.
The vulnerability, identified as CVE-2024-47561, affects all software versions older than 1.11.4.
According to a last-week advisory from the project maintainers, “Schema parsing in the Java SDK of Apache Avro 1.11.3 and earlier versions allows bad actors to execute arbitrary code.” It is advised that users update to versions 1.11.4 or 1.12.0, as these resolve this problem.
Like Google’s Protocol Buffers (protobuf), Apache Avro is an open-source project that offers a framework for language-neutral data serialization for large-scale data processing read more about Critical Apache Avro SDK Flaw Allows Remote Code Execution in Java Applications.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions
