Lucene search

K
cvelistApacheCVELIST:CVE-2022-35724
HistoryAug 09, 2022 - 6:50 a.m.

CVE-2022-35724 Denial of service while reading data in Avro Rust SDK

2022-08-0906:50:24
CWE-770
CWE-20
apache
www.cve.org
3
denial of service
avro sdk
rust applications
cve-2022-35724
apache avro

EPSS

0.001

Percentile

33.9%

It is possible to provide data to be read that leads the reader to loop in cycles endlessly, consuming CPU. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apache-avro version 0.14.0 which addresses this issue.

CNA Affected

[
  {
    "platforms": [
      "Rust"
    ],
    "product": "Apache Avro",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThan": "0.14.0",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

EPSS

0.001

Percentile

33.9%

Related for CVELIST:CVE-2022-35724