CVE-2022-36124 is a high-severity vulnerability affecting Rust applications using Apache Avro Rust SDK versions prior to 0.14.0. An unauthenticated attacker can exploit this flaw remotely to cause a denial of service by consuming excessive memory, leading to an out-of-memory condition. While no active exploitation or public exploit code has been identified, and community discussion is minimal, organizations should prioritize updating to version 0.14.0 to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.14.0CPE matchmatch criteria | cpe:2.3:a:apache:avro:*:*:*:*:*:rust:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.