It is possible to crash (panic) an application by providing a corrupted data to be read. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apache-avro version 0.14.0 which addresses this issue.
{ "nvd_published_at": "2022-08-09T07:15:00Z", "github_reviewed_at": "2022-08-18T19:14:55Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-190", "CWE-20" ] }