CVE-2025-30065 – org.apache.parquet:parquet-avro
Package
Manager: maven
Name: org.apache.parquet:parquet-avro
Vulnerable Version: >=0 <1.15.1
Severity
Level: Critical
CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A
EPSS: 0.00214 pctl0.44001
Details
Apache Parquet Avro Module Vulnerable to Arbitrary Code Execution Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrade to version 1.15.1, which fixes the issue.
Metadata
Created: 2025-04-01T09:30:20Z
Modified: 2025-05-07T17:39:39Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/04/GHSA-2c59-37c4-qrx5/GHSA-2c59-37c4-qrx5.json
CWE IDs: ["CWE-502"]
Alternative ID: GHSA-2c59-37c4-qrx5
Finding: F096
Auto approve: 1