216.73.217.22

CVE-2025-30065

· Published 01/04/2025 08:15 · Modified 01/04/2025 20:26

Labels: CVE-2025-30065 2025-04-01CVE-2025-30065CWE-502[email protected]

Essential information

Published
01/04/2025 08:15
Modified
01/04/2025 20:26
Author
Creator
CVSS
10.0 CRITICAL (v3) 10.0 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrade to version 1.15.1, which fixes the issue.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
apache / parquet cpe:2.3:a:apache:parquet:1.15.0:*:*:*:*:*:*:*
apache / parquet cpe:2.3:a:apache:parquet:<1.15.1:*:*:*:*:*:*:*

References