A critical security vulnerability in the Apache Avro Java Software Development Kit (SDK) could allow malicious code to be executed on vulnerable systems.

Apache Avro is an open-source project that provides a language-neutral data serialization framework for data .
The vulnerability, which was discovered, is tracked as CVE-2024-47561 and affects all versions of the software before 1.11.4.
See also: LiteSpeed Cache WordPress: New vulnerability allows XSS attacks
“Schema parsing in the Apache Avro Java SDK 1.11.3 and earlier versions allows malicious users to execute arbitrary code,” said last week. “Users are advised to upgrade to version 1.11.4 or 1.12.0 to fix this issue.”
The Avro team explained that the vulnerability affects any application that allows users to provide their own Avro schemas for parsing. Kostya Kortchinsky from the Databricks security team reportedly discovered and reported the vulnerability.
For protection, schema sanitization before parsing and avoiding parsing user-supplied schemas are recommended.
See also: CUPS vulnerability can be used in DDoS attacks
“The CVE-2024-47561 vulnerability affects Apache Avro 1.11.3 and earlier versions while de-serializing data received via the avroAvro schema,” said Mayuresh Dani, director of threat research at Qualys.

“Processing such inputs by a threat actor leads to code execution. Currently, no PoC is publicly available, but this vulnerability exists when processing packets via ReflectData and SpecificData directives and can also be exploited via Kafka,” he added.
The researcher explained that Apache Avro is used by many organizations, the majority of which are located in the US. This vulnerability highlights the importance of regularly updating software and addressing security. It also emphasizes the need for security measures, such as monitoring network traffic, to detect and prevent potential attacks.
Organizations should also consider implementing additional layers of protection, such as firewalls and intrusion detection systems, to further secure their systems.
See also: Jenkins fixes critical vulnerabilities in servers and plugins
Overall, it is important for organizations to prioritize cybersecurity and constantly work to keep their systems protected. By taking a proactive approach, organizations can protect their data and systems from potential threats.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: thehackernews.com
