CVE-2024-47561
published 2024-10-03CVE-2024-47561: Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code. Users are recommended to upgrade to…
PriorityP350high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
3.26%
86.9th percentile
Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code.
Users are recommended to upgrade to version 1.11.4 or 1.12.0, which fix this issue.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | avro | < 1.11.4 | 1.11.4 |
| apache_software_foundation | apache_avro_java_sdk | < 1.11.4 | 1.11.4 |
| atlassian | bamboo_data_center | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv4.09.2CRITICALCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat9.2CRITICAL
vendor_oracle5.9CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Hyperion Risk Matrix: Installation and Configuration (Apache Avro) — CVE-2024-47561
vendor_oracle·2025-07-15·CVSS 3.9
CVE-2024-47561 [CRITICAL] Oracle Oracle Hyperion Risk Matrix: Installation and Configuration (Apache Avro) — CVE-2024-47561
Oracle Oracle Hyperion Risk Matrix: Installation and Configuration (Apache Avro) vulnerability
CVE: CVE-2024-47561
CVSS: 3.9
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2025 (JUL 2025)
Oracle
Oracle Oracle GoldenGate Risk Matrix: Stream Analytics (Apache Avro) — CVE-2024-47561
vendor_oracle·2025-04-15·CVSS 3.8
CVE-2024-47561 [CRITICAL] Oracle Oracle GoldenGate Risk Matrix: Stream Analytics (Apache Avro) — CVE-2024-47561
Oracle Oracle GoldenGate Risk Matrix: Stream Analytics (Apache Avro) vulnerability
CVE: CVE-2024-47561
CVSS: 3.8
Protocol: HTTP
Remote exploit: No
Affected versions: Adjacent
Network
Advisory: cpuapr2025 (APR 2025)
Oracle
Oracle Oracle GoldenGate Risk Matrix: Java Delivery (Apache Avro) — CVE-2024-47561
vendor_oracle·2025-01-15·CVSS 5.9
CVE-2024-47561 [CRITICAL] Oracle Oracle GoldenGate Risk Matrix: Java Delivery (Apache Avro) — CVE-2024-47561
Oracle Oracle GoldenGate Risk Matrix: Java Delivery (Apache Avro) vulnerability
CVE: CVE-2024-47561
CVSS: 5.9
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpujan2025 (JAN 2025)
Atlassian
CVE-2024-47561: RCE (Remote Code Execution) org.apache.avro:avro Dependency in Bamboo Data Center and Server
vendor_atlassian·2024-11-19·CVSS 10.0
CVE-2024-47561 [CRITICAL] CVE-2024-47561: RCE (Remote Code Execution) org.apache.avro:avro Dependency in Bamboo Data Center and Server
CVE-2024-47561: RCE (Remote Code Execution) org.apache.avro:avro Dependency in Bamboo Data Center and Server
RCE (Remote Code Execution) org.apache.avro:avro Dependency in Bamboo Data Center and Server
CVE: CVE-2024-47561
Affected products: Bamboo Data Center
Red Hat
apache-avro: Schema parsing may trigger Remote Code Execution (RCE)
vendor_redhat·2024-10-03·CVSS 9.2
CVE-2024-47561 [CRITICAL] CWE-502 apache-avro: Schema parsing may trigger Remote Code Execution (RCE)
apache-avro: Schema parsing may trigger Remote Code Execution (RCE)
Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code.
Users are recommended to upgrade to version 1.11.4 or 1.12.0, which fix this issue.
A vulnerability was found in Apache Avro. The project is affected and at risk if it accepts an org.apache.Avro/avroAvro schema for parsing provided by an end user. This flaw allows an attacker to trigger remote code execution by using the special "java-class" attribute.
Statement: The Red Hat build of Apache Camel K 1.10 was rated Important as it allows users to provide an Avro schema for parsing. Note that this functionality is limited to authenticated users.
Red Hat Single Sign-On 7 ships the affected component in its
OSV
Apache Avro Java SDK: Arbitrary Code Execution when reading Avro Data (Java SDK)
osv·2024-10-03
CVE-2024-47561 [CRITICAL] Apache Avro Java SDK: Arbitrary Code Execution when reading Avro Data (Java SDK)
Apache Avro Java SDK: Arbitrary Code Execution when reading Avro Data (Java SDK)
Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code.
Users are recommended to upgrade to version 1.11.4 or 1.12.0, which fix this issue.
GHSA
Apache Avro Java SDK: Arbitrary Code Execution when reading Avro Data (Java SDK)
ghsa·2024-10-03
CVE-2024-47561 [CRITICAL] CWE-502 Apache Avro Java SDK: Arbitrary Code Execution when reading Avro Data (Java SDK)
Apache Avro Java SDK: Arbitrary Code Execution when reading Avro Data (Java SDK)
Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code.
Users are recommended to upgrade to version 1.11.4 or 1.12.0, which fix this issue.
No detection rules found.
No public exploits indexed.
Qualys
Oracle Critical Patch Update, April 2025 Security Update Review
blogs_qualys·2025-04-16
Oracle Critical Patch Update, April 2025 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Oracle released its first quarterly edition of this year’s Critical Patch Update. The update received patches for 378 s ecurity vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 103, constituting about 27% of the total patches released. Oracle MySQL and Oracle Communications Applications followed, with 43 and 42 security patches.
300 of the 378 security patches provided by the April Critical Patch Update (about 79%) are for non-Ora
Qualys
Oracle Critical Patch Update, April 2025 Security Update Review | Qualys
blogs_qualys·2025-04-16
Oracle Critical Patch Update, April 2025 Security Update Review | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
Oracle released its first quarterly edition of this year’s Critical Patch Update. The update received patches for 378 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address vulnerabilities in various product families, including third-party components in Oracle products.
In this quarterly Oracle Critical Patch Update, Oracle Communications received the highest number of patches, 103, constituting about 27% of the total patches released. Oracle MySQL and Oracle Communications Applications followed, with 43 and 42 security patches.
300 of the 378 security patches provided by the April Critical Patch Update (about 79%) are for non
Bugzilla
CVE-2024-47561 apache-avro: Schema parsing may trigger Remote Code Execution (RCE)
bugzilla·2024-10-02·CVSS 9.2
CVE-2024-47561 [CRITICAL] CVE-2024-47561 apache-avro: Schema parsing may trigger Remote Code Execution (RCE)
CVE-2024-47561 apache-avro: Schema parsing may trigger Remote Code Execution (RCE)
A vulnerability was found in Apache Avro. The project would be affected if it accepts an Avro schema for parsing
provided by the end-user. By using the special "java-class" attribute an attacker can trigger remote code execution.
The issue is fixed in Avro 1.11.4 and 1.12.0.
Discussion:
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform
Via RHSA-2024:7812 https://access.redhat.com/errata/RHSA-2024:7812
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9
Via RHS
2024-10-03
Published