CVE-2024-47561: Apache Avro
High severity, CVSS 7.3. EPSS: 3.3% chance of exploitation in the next 30 days.
Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code. Users are recommended to upgrade to version 1.11.4 or 1.12.0, which fix this issue.
Affected products
- Apache Avro: before 1.11.4 (fixed in 1.11.4)
- Netapp Active Iq Unified Manager: affected versions not specified
- Netapp Brocade San Navigator: affected versions not specified
Published 2024-10-03. Last modified 2026-06-17.