CVE-2021-43045
published 2022-01-06CVE-2021-43045: A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a denial-of-service attack. This issue…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.96%
85.7th percentile
A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a denial-of-service attack. This issue affects .NET applications using Apache Avro version 1.10.2 and prior versions. Users should update to version 1.11.0 which addresses this issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | avro | < 1.11.0 | 1.11.0 |
| apache_software_foundation | apache_avro | Apache Avro – 1.10.2 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Analytics Risk Matrix: Analytics Server (Apache Avro) — CVE-2021-43045
vendor_oracle·2023-10-15·CVSS 7.5
CVE-2021-43045 [HIGH] Oracle Oracle Analytics Risk Matrix: Analytics Server (Apache Avro) — CVE-2021-43045
Oracle Oracle Analytics Risk Matrix: Analytics Server (Apache Avro) vulnerability
CVE: CVE-2021-43045
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2023 (OCT 2023)
Red Hat
apache-avro: allows attackers to allocate excessive resources potentially causing a DoS
vendor_redhat·2022-01-06·CVSS 7.5
CVE-2021-43045 [HIGH] CWE-770 apache-avro: allows attackers to allocate excessive resources potentially causing a DoS
apache-avro: allows attackers to allocate excessive resources potentially causing a DoS
A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a denial-of-service attack. This issue affects .NET applications using Apache Avro version 1.10.2 and prior versions. Users should update to version 1.11.0 which addresses this issue.
Statement: CodeReady Studio is no longer supported and therefore this flaw will not be addressed in CodeReady Studio. Please see https://developers.redhat.com/articles/2022/04/18/announcement-red-hat-codeready-studio-reaches-end-life for more information.
Package: avro (Red Hat Fuse 7) - Not affected
Package: avro (Red Hat Integration Camel K 1) - Not affected
Package: avro (Red Hat Integration Servic
OSV
Allocation of Resources Without Limits or Throttling in Apache Avro
osv·2022-01-08
CVE-2021-43045 [HIGH] Allocation of Resources Without Limits or Throttling in Apache Avro
Allocation of Resources Without Limits or Throttling in Apache Avro
A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a denial-of-service attack. This issue affects .NET applications using Apache Avro version 1.10.2 and prior versions. Users should update to version 1.11.0 which addresses this issue.
GHSA
Allocation of Resources Without Limits or Throttling in Apache Avro
ghsa·2022-01-08
CVE-2021-43045 [HIGH] CWE-770 Allocation of Resources Without Limits or Throttling in Apache Avro
Allocation of Resources Without Limits or Throttling in Apache Avro
A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a denial-of-service attack. This issue affects .NET applications using Apache Avro version 1.10.2 and prior versions. Users should update to version 1.11.0 which addresses this issue.
No detection rules found.
No public exploits indexed.
2022-01-06
Published