Resource exhaustion in Apache Avro - CVE-2021-43045
Published: January 6, 2022
Vulnerability identifier: #VU59280
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-43045
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to .NET SDK of Apache Avro does not properly control consumption of internal resources. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Apache Avro
Oracle Business Intelligence Enterprise Edition
openEuler
avro
Cloudera Data Platform Private Cloud Base for IBM
Oracle Business Intelligence Enterprise Edition
openEuler
avro
Cloudera Data Platform Private Cloud Base for IBM
How to mitigate CVE-2021-43045
Install updates from vendor's website.
Apache Avro - update to 1.11.0
avro - update to 1.10.2-4
Cloudera Data Platform Private Cloud Base for IBM - update to 7.1.9.2
avro - update to 1.10.2-4
Cloudera Data Platform Private Cloud Base for IBM - update to 7.1.9.2