#VU83219 Deserialization of Untrusted Data in Apache Avro - CVE-2023-39410
Published: November 16, 2023
Apache Avro
Apache Foundation
Description
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to reader can consume memory beyond the allowed constraints and thus lead to out of memory on the system, when deserializing untrusted or corrupted data. A remote attacker can pass specially crafted data to the application and perform a denial of service attack.