HomeNewsHuge gap in huge information: Aparche Parquet has a ritical deserialization bug

Huge gap in huge information: Aparche Parquet has a ritical deserialization bug

Whereas the technical particulars of a possible exploit are but to come back, a particular module, Parquet-avro, inside the library was found permitting deserialization of untrusted information, enabling execution of codes despatched remotely within the type of crafted Parquet recordsdata.

Any utility or service that makes use of the Java library, together with fashionable big-data frameworks like Hadoop, Spark, and Flink are inclined to assaults. The ensuing distant code execution (RCE) on sufferer techniques can permit attackers to take management of the techniques, tamper with or steal information, set up malware, or/and disrupt companies, Endor labs added.

No identified exploits but

Neither Endor Labs nor NIST’s NVD entry reported any exploit makes an attempt utilizing CVE-2025-30065 as of publication of this text. Apache silently pushed a repair with the discharge of 1.15.1 on March 16, 2025, with a GitHub redirect to adjustments made within the replace.

See also  On-line Security Invoice passes remaining parliament debate, set to develop into UK legislation
- Advertisment -spot_img
RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -

Most Popular