Users are recommended to upgrade to version 1.11.4 or 1.12.0, which fix this issue.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3126 | Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code. Users are recommended to upgrade to version 1.11.4 or 1.12.0, which fix this issue. |
Github GHSA |
GHSA-r7pg-v2c8-mfg3 | Apache Avro Java SDK: Arbitrary Code Execution when reading Avro Data (Java SDK) |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 16 Jul 2025 22:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sun, 13 Jul 2025 22:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 22:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sat, 29 Mar 2025 00:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:quarkus:3.8::el8 |
Thu, 05 Dec 2024 11:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat quarkus
|
|
| CPEs | cpe:/a:redhat:quarkus:3.2::el8 | |
| Vendors & Products |
Redhat quarkus
|
Mon, 25 Nov 2024 23:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat jboss Enterprise Application Platform Eus
|
|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7 cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7 |
|
| Vendors & Products |
Redhat jboss Enterprise Application Platform Eus
|
Fri, 22 Nov 2024 21:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 23 Oct 2024 11:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat camel K
|
|
| CPEs | cpe:/a:redhat:camel_k:1.10.8 | |
| Vendors & Products |
Redhat camel K
|
Mon, 21 Oct 2024 18:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV4_0
|
Tue, 15 Oct 2024 11:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat apache Camel Spring Boot
|
|
| CPEs | cpe:/a:redhat:apache_camel_spring_boot:4.4.3 | |
| Vendors & Products |
Redhat apache Camel Spring Boot
|
Fri, 11 Oct 2024 11:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat camel Quarkus
|
|
| CPEs | cpe:/a:redhat:camel_quarkus:3.8 | |
| Vendors & Products |
Redhat camel Quarkus
|
Thu, 10 Oct 2024 11:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat apicurio Registry
|
|
| CPEs | cpe:/a:redhat:apicurio_registry:2.6 | |
| Vendors & Products |
Redhat apicurio Registry
|
Wed, 09 Oct 2024 23:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat jboss Enterprise Application Platform |
|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform:7.4 cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7 cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8 cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9 |
|
| Vendors & Products |
Redhat
Redhat jboss Enterprise Application Platform |
Fri, 04 Oct 2024 22:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 04 Oct 2024 04:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache avro |
|
| CPEs | cpe:2.3:a:apache:avro:-:*:*:*:*:-:*:* | |
| Vendors & Products |
Apache
Apache avro |
|
| Metrics |
cvssV3_1
|
Thu, 03 Oct 2024 19:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code. Users are recommended to upgrade to version 1.11.4 or 1.12.0, which fix this issue. | |
| Title | Apache Avro Java SDK: Arbitrary Code Execution when reading Avro schema (Java SDK) | |
| Weaknesses | CWE-502 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-10-21T08:51:22.972Z
Reserved: 2024-09-27T07:06:47.522Z
Link: CVE-2024-47561
Updated: 2024-10-11T22:03:16.050Z
Status : Analyzed
Published: 2024-10-03T11:15:13.510
Modified: 2025-07-10T21:04:01.920
Link: CVE-2024-47561
OpenCVE Enrichment
No data.
EUVD
Github GHSA