High severityNVD Advisory· Published Jan 6, 2022· Updated Aug 4, 2024
Possible DOS vulnerabilities in C# Avro SDK
CVE-2021-43045
Description
A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a denial-of-service attack. This issue affects .NET applications using Apache Avro version 1.10.2 and prior versions. Users should update to version 1.11.0 which addresses this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Apache.AvroNuGet | < 1.11.0 | 1.11.0 |
Affected products
2Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-868x-rg4c-cjqgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-43045ghsaADVISORY
- www.openwall.com/lists/oss-security/2022/01/06/8ghsamailing-listx_refsource_MLISTWEB
- github.com/apache/avro/pull/1357ghsaWEB
- issues.apache.org/jira/browse/AVRO-3225ghsaWEB
- issues.apache.org/jira/browse/AVRO-3226ghsaWEB
- lists.apache.org/thread/5fttw9vk6gd2p3b846nox7hcj5469xfdghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.