Apache Avro是美国阿帕奇(Apache)基金会的一个数据序列化系统。为 Apache Hadoop 提供数据序列化和数据交换服务。 Apache Avro 中存在资源管理错误漏洞,该漏洞源于产品的.net SDK组件未对分配资源量进行有效限制。攻击者可通过该漏洞分配过多资源导致拒绝服务。以下产品及版本受到影响: Apache Avro 1.10.2 版本及之前版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Avro | Apache Avro ~ 1.10.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-45458 | Hardcoded credentials | |
| CVE-2021-45457 | Overly broad CORS configuration | |
| CVE-2021-45456 | Command injection | |
| CVE-2021-36774 | Mysql JDBC Connector Deserialize RCE | |
| CVE-2021-31522 | Apache Kylin unsafe class loading | |
| CVE-2021-27738 | Improper Access Control to Streaming Coordinator & SSRF | |
| CVE-2021-36739 | XSS vulnerability in the MVCBean JSP portlet maven archetype | |
| CVE-2021-36738 | XSS vulnerability in the JSP version of the Apache Pluto Applicant MVCBean CDI portlet | |
| CVE-2021-36737 | XSS in V3 Demo Portlet |
No comments yet