First published: Thu Jan 06 2022(Updated: )
A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a denial-of-service attack. This issue affects .NET applications using Apache Avro version 1.10.2 and prior versions. Users should update to version 1.11.0 which addresses this issue.
Credit: security@apache.org security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
nuget/Apache.Avro | <1.11.0 | 1.11.0 |
Apache Avro | <1.11.0 | |
<1.11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-43045.
The severity rating of CVE-2021-43045 is high with a value of 7.5.
CVE-2021-43045 affects .NET applications using Apache Avro version 1.10.2 and prior versions.
To fix CVE-2021-43045, users should update to version 1.11.0 of Apache Avro.
You can find more information about CVE-2021-43045 on the NVD website: https://nvd.nist.gov/vuln/detail/CVE-2021-43045