Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-30065

Опубликовано: 01 апр. 2025
Источник: redhat
CVSS3: 10
EPSS Низкий

Описание

Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrade to version 1.15.1, which fixes the issue.

A flaw was found in the parquet-avro module of Apache Parquet. This vulnerability allows attackers to execute arbitrary code via schema parsing.

Отчет

Camel Spring Boot product is not affected by this vulnerability since the listed components are not supported.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel for Spring Boot 4camel-parquet-avroNot affected
Red Hat build of Apache Camel for Spring Boot 4parquet-avroNot affected

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=2356519org.apache.parquet/parquet-avro: Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata

EPSS

Процентиль: 51%
0.00276
Низкий

10 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
5 месяцев назад

Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrade to version 1.15.1, which fixes the issue.

github
5 месяцев назад

Apache Parquet Avro Module Vulnerable to Arbitrary Code Execution

CVSS3: 10
fstec
5 месяцев назад

Уязвимость модуля parquet-avro формата столбцового хранения для обработки данных Apache Parquet Java, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 51%
0.00276
Низкий

10 Critical

CVSS3