AI
AI

Major Vulnerability Identified in Apache Parquet: Critical Deserialization Bug

Photo credit: www.csoonline.com

A critical vulnerability has been identified within the Parquet-avro module of a widely used Java library, which poses significant risks to applications leveraging it. This flaw permits the deserialization of untrusted data, potentially allowing attackers to execute unauthorized code through specially crafted Parquet files.

The implications of this vulnerability are severe, particularly for applications and services that utilize the Java library, including major big-data frameworks like Hadoop, Spark, and Flink. Should an attacker exploit this remote code execution (RCE) vulnerability on affected systems, they could gain unauthorized control, manipulate or exfiltrate sensitive data, deploy malware, or disrupt operations, as noted by security experts at Endor Labs.

Current Status of Exploits

As of the latest reports, neither Endor Labs nor the National Institute of Standards and Technology (NIST) has observed any active exploitations related to CVE-2025-30065. This information is outlined in the NVD entry, which confirms that no attacks have been publicly documented. In response to this discovery, Apache swiftly released a patch, incorporating the necessary fixes in version 1.15.1 on March 16, 2025. Details of the changes can be explored further through the GitHub page associated with this update.

Source
www.csoonline.com

Related by category

Broadcom-Supported SAN Devices Vulnerable to Code Injection Attacks Due to Critical Fabric OS Flaw

Photo credit: www.csoonline.com Critical Vulnerability Found in Broadcom’s Brocade Fabric...

Cyberattack on berlin.de | CSO Online

Photo credit: www.csoonline.com Cyberangriff auf Berlins Info- und Serviceportal berlin.de Ende...

The Rising Tide of Intrusions: Increased Stolen Credentials and Perimeter Exploits Amid Declining Phishing Attacks

Photo credit: www.csoonline.com The landscape of cybersecurity continues to evolve,...

Latest news

White House Budget Office “Unresponsive” to Investigations Regarding Frozen Funds, GAO Report Reveals

Photo credit: thehill.com GAO Chief Highlights Challenges in Accessing Information...

Classic Crepes Suzette with a Vibrant Twist Using This Everyday Ingredient!

Photo credit: www.seriouseats.com Classic Crêpes Suzette with a Colorful Twist Why...

Taylor Swift Appears Youthful in 2015 Snapshot with Ed Sheeran

Photo credit: www.instyle.com Ed Sheeran Shares Throwback Photo of Young...

Breaking news