CVE-2022-35724
Apache Avro Rust SDK vulnerable to reader looping in cycle endlessly, consuming CPU
7.5
HIGH
CVSS 3.1
EPSS 0.70%
Description
It is possible to provide data to be read that leads the reader to loop in cycles endlessly, consuming CPU. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apache-avro version 0.14.0 which addresses this issue.
How to fix CVE-2022-35724
To remediate CVE-2022-35724, upgrade the affected package to a fixed version below.
- —upgrade to 0.14.0 or later
Is CVE-2022-35724 being exploited?
Low — EPSS is 0.7%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.14.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |