It is possible to crash (panic) an application by providing a corrupted data to be read. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apache-avro version 0.14.0 which addresses this issue.
{
"nvd_published_at": "2022-08-09T07:15:00Z",
"severity": "HIGH",
"cwe_ids": [
"CWE-190",
"CWE-20"
],
"github_reviewed": true,
"github_reviewed_at": "2022-08-18T19:14:55Z"
}