Input validation error in Apache Avro - CVE-2024-47561

 

Input validation error in Apache Avro - CVE-2024-47561

Published: October 3, 2024 / Updated: October 15, 2024


Vulnerability identifier: #VU98024
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-47561
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient validation of user-supplied input when parsing schema in Java SDK. A remote attacker can pass specially crafted schema to the application and execute arbitrary code on the system.


Affected software

Apache Avro
Oracle GoldenGate Big Data and Application Adapters
Operations Analytics - Log Analysis
Guardium Data Security Center (GDSC)
DataStage on Cloud Pak for Data
Oracle Business Intelligence Enterprise Edition
IBM Event Endpoint Management
Business Automation Insights
IBM Application Suite - IBM Asset Data Dictionary Component
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
watsonx Assistant Cartridge
Cognos Dashboards on Cloud Pak for Data
Netcool Operations Insight
Red Hat Integration Camel-K
IBM Watson Knowledge Catalog in Cloud Pak for Data
Jira Service Management Data Center
Jira Service Management Server
Confluence Data Center
Bitbucket Data Center
Logstash
Jira Software Data Center
Bamboo Server
Infrastructure Technology
Red Hat Integration - Service Registry
Red Hat build of Quarkus
IBM Cloud Application Performance Management (APM)
IBM Cloud Pak for Business Automation
IBM Disconnected Log Collector
Apache Pulsar
Communications Unified Assurance
JBoss Enterprise Application Platform
Bitbucket Server
Confluence Server
Jira Software Server
Oracle Business Process Management Suite
Oracle SOA Suite
Stream Analytics
openEuler
eap7-jboss-annotations (Red Hat package)
eap7-log4j-jboss-logmanager (Red Hat package)
eap7-h2database (Red Hat package)
eap7-jboss-server-migration (Red Hat package)
eap7-avro (Red Hat package)
avro
eap7-bouncycastle (Red Hat package)
eap7-jboss-marshalling (Red Hat package)
eap7-xml-security (Red Hat package)
eap7-wss4j (Red Hat package)
eap7-xalan-j2 (Red Hat package)
eap7-jackson-databind (Red Hat package)
eap7-apache-cxf (Red Hat package)
eap7-jboss-xnio-base (Red Hat package)
eap7-wildfly (Red Hat package)
Red Hat Camel for Spring Boot

How to mitigate CVE-2024-47561

Install updates from vendor's website.

Apache Avro - addressed in versions 1.11.4, 1.12.0
Operations Analytics - Log Analysis - update to 1.3.8.0.1
Netcool Operations Insight - update to 1.6.15
IBM Disconnected Log Collector - update to 1.8.7
Red Hat Integration Camel-K - update to 1.10.8
Apache Pulsar - addressed in versions 3.0.7, 3.3.2
Guardium Data Security Center (GDSC) - update to 3.6.1
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.1, 5.1.2, 5.1.3
DataStage on Cloud Pak for Data - update to 4.8.9
Jira Service Management Data Center - addressed in versions 5.12.15, 5.17.5, 10.3.1
Jira Service Management Server - addressed in versions 5.12.15, 5.17.5, 10.3.1
JBoss Enterprise Application Platform - addressed in versions 7.1.8, 7.3.11
Confluence Server - addressed in versions 7.19.30, 8.5.18, 8.9.8, 9.1.1
Confluence Data Center - addressed in versions 7.19.30, 8.5.18, 8.9.8, 9.1.1
Bitbucket Data Center - addressed in versions 8.9.21, 8.19.11
Bitbucket Server - addressed in versions 8.9.21, 8.19.11
Logstash - update to 8.15.3
Jira Software Data Center - addressed in versions 9.12.15, 9.17.5, 10.3.1
Jira Software Server - addressed in versions 9.12.15, 9.17.5, 10.3.1
Bamboo Server - addressed in versions 9.2.20, 9.6.8, 10.0.3
IBM Event Endpoint Management - update to 11.3.1
Business Automation Insights - update to 24.0.0.0.2
eap7-jboss-annotations (Red Hat package) - update to api_1.3_spec-2.0.1-4.Final_redhat_00001.1.el7eap
Red Hat Integration - Service Registry - update to 1
IBM Application Suite - IBM Asset Data Dictionary Component - update to 1.1.15
eap7-log4j-jboss-logmanager (Red Hat package) - update to 1.2.2-2.Final_redhat_00002.1.el7eap
eap7-h2database (Red Hat package) - addressed in versions 1.4.197-2.redhat_00005.1.ep7.el7, 1.4.197-3.redhat_00004.1.el7eap
eap7-jboss-server-migration (Red Hat package) - update to 1.7.2-12.Final_redhat_00013.1.el7eap
eap7-avro (Red Hat package) - addressed in versions 1.7.6-2.redhat_00003.1.ep7.el7, 1.7.6-8.redhat_00003.1.el7eap, 1.11.4-1.redhat_00001.1.el7eap, 1.11.4-1.redhat_00001.1.el8eap, 1.11.4-1.redhat_00001.1.el9eap
avro - update to 1.10.2-6
eap7-bouncycastle (Red Hat package) - update to 1.68.0-1.redhat_00005.1.ep7.el7
eap7-jboss-marshalling (Red Hat package) - addressed in versions 2.0.15-1.Final_redhat_00001.1.el7eap, 2.0.15-1.Final_redhat_00001.1.ep7.el7
eap7-xml-security (Red Hat package) - update to 2.2.3-2.redhat_00001.1.el7eap
eap7-wss4j (Red Hat package) - update to 2.3.3-2.redhat_00001.1.el7eap
eap7-xalan-j2 (Red Hat package) - addressed in versions 2.7.1-26.redhat_00015.1.ep7.el7, 2.7.1-38.redhat_00015.1.el7eap
eap7-jackson-databind (Red Hat package) - update to 2.8.11.6-1.SP1_redhat_00001.1.ep7.el7
eap7-apache-cxf (Red Hat package) - addressed in versions 3.1.16-3.SP1_redhat_00001.1.ep7.el7, 3.4.10-1.SP1_redhat_00001.1.el7eap
Red Hat build of Quarkus - addressed in versions 3.2.12.SP1, 3.8.6.SP1
eap7-jboss-xnio-base (Red Hat package) - addressed in versions 3.5.10-1.Final_redhat_00001.1.ep7.el7, 3.7.13-1.Final_redhat_00001.1.el7eap
Red Hat Camel for Spring Boot - addressed in versions 4.4.0, 4.4.3
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.1.1
watsonx Assistant Cartridge - update to 5.1.1
Cognos Dashboards on Cloud Pak for Data - update to 5.1.1
eap7-wildfly (Red Hat package) - addressed in versions 7.1.8-2.GA_redhat_00002.1.ep7.el7, 7.3.11-4.GA_redhat_00002.1.el7eap
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.17
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1

External References

Related Security Bulletins