AI description
CVE-2025-30065 is a vulnerability in the Apache Parquet Java library, specifically within the parquet-avro module. It stems from insecure deserialization of untrusted data during schema parsing. This flaw affects Apache Parquet versions up to and including 1.15.0. Successful exploitation of this vulnerability could allow an attacker to achieve remote code execution (RCE) on a vulnerable system. This can occur if a system is tricked into reading a specially crafted Parquet file. It is recommended to upgrade to version 1.15.1, which addresses the issue.
- Description
- Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrade to version 1.15.1, which fixes the issue.
- Source
- security@apache.org
- NVD status
- Awaiting Analysis
CVSS 4.0
- Type
- Secondary
- Base score
- 10
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
- security@apache.org
- CWE-502
- Hype score
- Not currently trending
Parquet files power Big Data & Cloud, but new vulnerabilities like CVE-2025-30065 mean security is a must! Learn about risks, mitigations, and how to validate your Parquet data in my latest article via @DZoneInc. #CloudSecurity #BigData https://t.co/qVks1ANfLM
@morusu_v
24 Apr 2025
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Actively exploited CVE : CVE-2025-30065
@transilienceai
20 Apr 2025
17 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
A critical vulnerability (CVE-2025-30065) in the Apache Parquet's parquet-avro module poses a significant risk, allowing attackers to execute arbitrary code through maliciously crafted Parquet files. Major organizations using Parquet for data processing could face severe conse...
@CybrPulse
16 Apr 2025
26 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
A critical vulnerability (CVE-2025-30065) in the Apache Parquet's parquet-avro module poses a significant risk, allowing attackers to execute arbitrary code through maliciously crafted Parquet files. Major organizations using Parquet for data processing could face severe conse...
@CybrPulse
15 Apr 2025
30 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Two critical vulnerabilities (CVE-2025-24859 and CVE-2025-30065, both with a CVSS score of 10) threaten the securities of systems using Apache Roller and Apache Parquet. Apache Roller allows unauthorized access even after password changes due to a session management flaw, whil...
@CybrPulse
15 Apr 2025
18 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🚨 CRITICAL SECURITY ALERT 🚨 Apache Parquet Java library contains a severe Remote Code Execution vulnerability (CVE-2025-30065) discovered on April 2, 2025. The flaw in the parquet-avro module allows attackers to execute arbitrary code on affected systems. If you're using http
@ThreatRadarAI
14 Apr 2025
46 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CRITICAL SECURITY ALERT🚨 Apache Parquet Java library contains a severe Remote Code Execution vulnerability(CVE-2025-30065) discovered on April 2, 2025. The flaw in the parquet-avro module allows attackers to execute arbitrary code on affected systems. #ApacheParquet #CVE #RCE
@ThreatRadarAI
14 Apr 2025
10 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Actively exploited CVE : CVE-2025-30065
@transilienceai
12 Apr 2025
14 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Actively exploited CVE : CVE-2025-30065
@transilienceai
11 Apr 2025
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Measured analysis of Apache Parquet CVE-2025-30065 by @the_emmons: "Feels like a clever red team exploit....it requires expertise and time to weaponize, and RCE isn’t a sure thing even if you do get a Parquet file deserialized by a vulnerable instance." https://t.co/h9lZ4XrUjG
@catc0n
11 Apr 2025
927 Impressions
6 Retweets
20 Likes
3 Bookmarks
0 Replies
0 Quotes
🚨 Massive new risk for data systems! CVE-2025-30065 | Apache Parquet Java lib flaw (CVSS 10.0) lets attackers execute arbitrary code via poisoned files. If your pipelines touch untrusted Parquet files, patch NOW. https://t.co/Z02g16z5eD
@achi_tech
8 Apr 2025
23 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨Nueva vulnerabilidad: CVE-2025-30065 en la librería Java de Apache Parquet (CVSS 10.0) permite a atacantes ejecutar código arbitrario a través de ficheros manipulados. Si tus pipelines procesan archivos Parquet de fuentes no confiables, parchea. Más info aquí:
@Cyph3R_CyberSec
7 Apr 2025
26 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Apache Parquetで重大な脆弱性、対象者はアップデートを(CVE-2025-30065) #セキュリティ対策Lab #セキュリティ #Security https://t.co/L2iK6W67hR
@securityLab_jp
7 Apr 2025
45 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
こんばんは、いかがお過ごしでしょうか「今宵のサイバーセキュリティーについて気になること」情シス部門のゼロトラスト導入に向けて#7 改善活動について考えてみよう、Oracle社が情報漏洩を隠蔽しようとした疑惑、Apache Parquet RCE脆弱性CVE-2025-30065 CVSS10.0 などをお伝えします。 https://t.co/MUuyS6aGAo
@t_nihonmatsu
6 Apr 2025
1981 Impressions
1 Retweet
10 Likes
0 Bookmarks
1 Reply
1 Quote
Guidance for handling CVE-2025-30065 using Microsoft Security capabilities https://t.co/zWtJ8191S0 #Microsoft #techcommunity
@MSITTechNews
6 Apr 2025
34 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
#exploit 1. CVE-2025-2748: XSS To RCE By Abusing Custom File Handlers - Kentico Xperience CMS https://t.co/bMnlsnb4Vd 2. CVE-2025-44228: AnyDesk RCE PoC https://t.co/vGlZNwGVFD 3. CVE-2025-30065: Apache Parquet RCE https://t.co/0uZP5a053F
@ksg93rd
6 Apr 2025
622 Impressions
2 Retweets
11 Likes
7 Bookmarks
0 Replies
0 Quotes
CVE-2025-30065 Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrad… https://t.co/vBDcnQHrMI
@CVEnew
5 Apr 2025
528 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Vulnerabilidade Crítica no Apache Parquet e Ataques a Servidores Tomcat 1. Vulnerabilidade no Apache Parquet (CVE-2025-30065): - Gravidade: CVSS 10.0 (crítica). - Impacto: Permite execução remota de código arbitrário via arquivos Parquet maliciosos.
@pedroco53915492
5 Apr 2025
12 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Critical security alert for Apache Parquet users! A new max-severity flaw (CVE-2025-30065) could let attackers execute arbitrary code. Patch to version 1.15.1 immediately! https://t.co/ORamrFK2dw https://t.co/PUUdHZ34Sg
@troyCyber_
5 Apr 2025
17 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
A maximum severity remote code execution (RCE) vulnerability has been discovered impacting all versions of Apache Parquet up to and including 1.15.0. The vulnerability is tracked under CVE-2025-30065 and has a CVSS v4 score of 10.0. https://t.co/R1BMRjM38d https://t.co/Ih0PtvYHT7
@riskigy
5 Apr 2025
26 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-30065 : ข้อบกพร่อง RCE ความรุนแรงสูงสุดที่ค้นพบในปาร์เก้ Apache ที่ใช้กันอย่างแพร่หลาย https://t.co/MiSlPj6Vin
@freedomhack101
5 Apr 2025
11 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-30065 impacts Apache Parquet #ApacheParaquet #CVE-2025-30065 https://t.co/NAourLz3Zz
@pravin_karthik
5 Apr 2025
31 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
A maximum severity RCE vulnerability (CVSS 10.0) has been discovered, impacting all versions of Apache Parquet <= v1.15.0. CVE-2025-30065 https://t.co/oR9IowMESz
@t3l3machus
5 Apr 2025
827 Impressions
5 Retweets
7 Likes
2 Bookmarks
0 Replies
0 Quotes
ثغرة جديدة على Apache Parquet CVE-2025-30065 نوعها RCE و مستوى الخطورة 10 🔥 وكل الاصدارات الى 1.15.0 مصابة تم إغلاق الثغرة في تحديث 1.15.1 التحديث مهم جدا https://t.co/hUHQ32aOzV
@HereHuss
5 Apr 2025
30 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Vulnerabilidad crítica en Apache Parquet Java via 1.15.0 ⚠️ CVE-2025-30065 https://t.co/foqYNktm6w https://t.co/uWRXESReNr
@elhackernet
4 Apr 2025
1714 Impressions
3 Retweets
7 Likes
0 Bookmarks
0 Replies
0 Quotes
GitHub - bjornhels/CVE-2025-30065: PoC - https://t.co/WYOq1fwxjM
@piedpiper1616
4 Apr 2025
5020 Impressions
22 Retweets
60 Likes
18 Bookmarks
0 Replies
1 Quote
⚠️ A critical #vulnerability (CVE-2025-30065) in Apache Parquet's Java Library could allow remote code execution on vulnerable instances. This issue has a maximum CVSS score of 10.0 🤖 #flaw https://t.co/w7VTsPVylo
@manuelbissey
4 Apr 2025
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
A critical vulnerability, CVE-2025-30065, in the Apache Parquet Java library could allow remote code execution, impacting systems that process untrusted Parquet files. With a CVSS score of 10.0, organizations must quickly upgrade to version 1.15.1 to avoid severe threats, incl...
@CybrPulse
4 Apr 2025
30 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🗞️ Critical RCE Flaw in Apache Parquet Exposes Big Data Systems to Attack A max-severity RCE flaw (CVE-2025-30065) in Apache Parquet up to v1.15.0 threatens big data platforms like Hadoop and cloud services—upgrade to 1.15.1 ASAP to stay safe! There are no active exploits yet,
@gossy_84
4 Apr 2025
68 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
A critical vulnerability designated CVE-2025-30065 has been discovered in Apache Parquet, with a CVSS score of 10.0, potentially allowing attackers to execute malicious code by leveraging vulnerable applications that process Parquet files. Admins are urged to apply the securit...
@CybrPulse
4 Apr 2025
29 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
広く使用されているApache Parquetで最大の重大度のRCE脆弱性が発見される(CVE-2025-30065) https://t.co/qWOI5lHvkV #Security #セキュリティ #ニュース
@SecureShield_
4 Apr 2025
37 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
📢 CiberSeguridad en menos de 5 minutos 🧱 Apache Parquet vulnerable a RCE – CVE-2025-30065 permite ejecución remota al procesar archivos manipulados; afecta múltiples plataformas de big data. 🎭 Hunters International ahora es World Leaks – Se enfocan en extorsión sin cifrado, h
@Seifreed
4 Apr 2025
508 Impressions
2 Retweets
18 Likes
2 Bookmarks
0 Replies
0 Quotes
A critical vulnerability (CVE-2025-30065) in Apache Parquet allows remote code execution via crafted files. Affects versions up to 1.15.0; patched in 1.15.1. Risk to data pipelines is significant. ⚠️ #Apache #DataSecurity #USA link: https://t.co/kFP6D7Rejf https://t.co/nEjyRp9Iz
@TweetThreatNews
4 Apr 2025
36 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
A severe vulnerability in Apache Parquet's Java Library (CVE-2025-30065) has been disclosed, rated with a critical CVSS score of 10.0, allowing potential remote code execution through specially crafted Parquet files. While no known attacks have been reported yet, the risk is s...
@CybrPulse
4 Apr 2025
33 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Apache Parquet RCE脆弱性CVE-2025-30065 CVSS10.0信頼できないデータのデシリアライズに起因しており、バージョン 1.15.1 のリリースで修正されました。これは Parquet ファイルをインポートするすべてのデータ パイプラインと分析システムに影響を与える可能性があります。 https://t.co/Si6iFaoydR
@t_nihonmatsu
3 Apr 2025
198 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🔴 Una vulnerabilidad de ejecución remota de código (RCE) de máxima gravedad (CVE-2025-30065) afecta hoy a todas las versiones de Apache Parquet hasta la 1.15.0 inclusive. 🧉 https://t.co/SebuB1aIX8
@MarquisioX
3 Apr 2025
49 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-30065 (CVSS 10): Critical Vulnerability Discovered in Apache Parquet Java https://t.co/a45n3sq4jz
@Dinosn
2 Apr 2025
2556 Impressions
8 Retweets
11 Likes
6 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2025-30065 ⚠️🔴 CRITICAL (10) 🏢 Apache Software Foundation - Apache Parquet Java 🏗️ 0 🔗 https://t.co/8DUwqaa4ab #CyberCron #VulnAlert #InfoSec https://t.co/0wDNbd69xT
@cybercronai
1 Apr 2025
49 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[CVE-2025-30065: CRITICAL] Apache Parquet 1.15.0 and earlier versions are vulnerable to arbitrary code execution due to a flaw in the parquet-avro module. Upgrade to version 1.15.1 for a fix.#cybersecurity,#vulnerability https://t.co/bulUKpWxv2 https://t.co/cI4YIHheZN
@CveFindCom
1 Apr 2025
30 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes