v1.10.9.md 707 字节
Newer Older
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25
# Dapr 1.10.9 [security]

This update contains security fixes:

  - [Security: Potential DoS in avro dependency (CVE-2023-37475)](#security-potential-dos-in-avro-dependency-cve-2023-37475)

## Security: Potential DoS in avro dependency (CVE-2023-37475)

### Problem

[CVE-2023-37475](https://github.com/hamba/avro/security/advisories/GHSA-9x44-9pgq-cf45)

An issue in the third-party avro dependency could cause a resource exhaustion and a DoS for Dapr.

### Impact

This issue impacts users of Dapr that use the Pulsar components.

### Root cause

The issue was in a third-party dependency.

### Solution

We have upgraded the avro dependency to version 2.13.0 which contains a fix for the reported issue.