HomeSecurityWarning! Critical vulnerability in Apache Avro Java SDK

Warning! Critical vulnerability in Apache Avro Java SDK

A critical security vulnerability in the Apache Avro Java Software Development Kit (SDK) could allow malicious code to be executed on vulnerable systems.

Apache Avro Java vulnerability

Apache Avro is an open-source project that provides a language-neutral data serialization framework for data .

The vulnerability, which was discovered, is tracked as CVE-2024-47561 and affects all versions of the software before 1.11.4.

See also: LiteSpeed ​​Cache WordPress: New vulnerability allows XSS attacks

“Schema parsing in the Apache Avro Java SDK 1.11.3 and earlier versions allows malicious users to execute arbitrary code,” said last week. “Users are advised to upgrade to version 1.11.4 or 1.12.0 to fix this issue.”

The Avro team explained that the vulnerability affects any application that allows users to provide their own Avro schemas for parsing. Kostya Kortchinsky from the Databricks security team reportedly discovered and reported the vulnerability.

For protection, schema sanitization before parsing and avoiding parsing user-supplied schemas are recommended.

See also: CUPS vulnerability can be used in DDoS attacks

“The CVE-2024-47561 vulnerability affects Apache Avro 1.11.3 and earlier versions while de-serializing data received via the avroAvro schema,” said Mayuresh Dani, director of threat research at Qualys.

Warning! Critical vulnerability in Apache Avro Java SDK

“Processing such inputs by a threat actor leads to code execution. Currently, no PoC is publicly available, but this vulnerability exists when processing packets via ReflectData and SpecificData directives and can also be exploited via Kafka,” he added.

The researcher explained that Apache Avro is used by many organizations, the majority of which are located in the US. This vulnerability highlights the importance of regularly updating software and addressing security. It also emphasizes the need for security measures, such as monitoring network traffic, to detect and prevent potential attacks.

Organizations should also consider implementing additional layers of protection, such as firewalls and intrusion detection systems, to further secure their systems.

See also: Jenkins fixes critical vulnerabilities in servers and plugins

Overall, it is important for organizations to prioritize cybersecurity and constantly work to keep their systems protected. By taking a proactive approach, organizations can protect their data and systems from potential threats.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS