CVE-2025-30065

Published Apr 1, 2025

Last updated a month ago

CVSS critical 10.0
Apache Parquet
Java

Overview

AI description

Generated using AI and has not been reviewed by Intruder. May contain errors.

CVE-2025-30065 is a vulnerability in the Apache Parquet Java library, specifically within the parquet-avro module. It stems from insecure deserialization of untrusted data during schema parsing. This flaw affects Apache Parquet versions up to and including 1.15.0. Successful exploitation of this vulnerability could allow an attacker to achieve remote code execution (RCE) on a vulnerable system. This can occur if a system is tricked into reading a specially crafted Parquet file. It is recommended to upgrade to version 1.15.1, which addresses the issue.

Description
Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrade to version 1.15.1, which fixes the issue.
Source
security@apache.org
NVD status
Awaiting Analysis

Risk scores

CVSS 4.0

Type
Secondary
Base score
10
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

Weaknesses

security@apache.org
CWE-502

Social media

Hype score
Not currently trending
  1. Parquet files power Big Data & Cloud, but new vulnerabilities like CVE-2025-30065 mean security is a must! Learn about risks, mitigations, and how to validate your Parquet data in my latest article via @DZoneInc. #CloudSecurity #BigData https://t.co/qVks1ANfLM

    @morusu_v

    24 Apr 2025

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Actively exploited CVE : CVE-2025-30065

    @transilienceai

    20 Apr 2025

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. A critical vulnerability (CVE-2025-30065) in the Apache Parquet's parquet-avro module poses a significant risk, allowing attackers to execute arbitrary code through maliciously crafted Parquet files. Major organizations using Parquet for data processing could face severe conse...

    @CybrPulse

    16 Apr 2025

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. A critical vulnerability (CVE-2025-30065) in the Apache Parquet's parquet-avro module poses a significant risk, allowing attackers to execute arbitrary code through maliciously crafted Parquet files. Major organizations using Parquet for data processing could face severe conse...

    @CybrPulse

    15 Apr 2025

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Two critical vulnerabilities (CVE-2025-24859 and CVE-2025-30065, both with a CVSS score of 10) threaten the securities of systems using Apache Roller and Apache Parquet. Apache Roller allows unauthorized access even after password changes due to a session management flaw, whil...

    @CybrPulse

    15 Apr 2025

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. 🚨 CRITICAL SECURITY ALERT 🚨 Apache Parquet Java library contains a severe Remote Code Execution vulnerability (CVE-2025-30065) discovered on April 2, 2025. The flaw in the parquet-avro module allows attackers to execute arbitrary code on affected systems. If you're using http

    @ThreatRadarAI

    14 Apr 2025

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨 CRITICAL SECURITY ALERT🚨 Apache Parquet Java library contains a severe Remote Code Execution vulnerability(CVE-2025-30065) discovered on April 2, 2025. The flaw in the parquet-avro module allows attackers to execute arbitrary code on affected systems. #ApacheParquet #CVE #RCE

    @ThreatRadarAI

    14 Apr 2025

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Actively exploited CVE : CVE-2025-30065

    @transilienceai

    12 Apr 2025

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  9. Actively exploited CVE : CVE-2025-30065

    @transilienceai

    11 Apr 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  10. Measured analysis of Apache Parquet CVE-2025-30065 by @the_emmons: "Feels like a clever red team exploit....it requires expertise and time to weaponize, and RCE isn’t a sure thing even if you do get a Parquet file deserialized by a vulnerable instance." https://t.co/h9lZ4XrUjG

    @catc0n

    11 Apr 2025

    927 Impressions

    6 Retweets

    20 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  11. 🚨 Massive new risk for data systems! CVE-2025-30065 | Apache Parquet Java lib flaw (CVSS 10.0) lets attackers execute arbitrary code via poisoned files. If your pipelines touch untrusted Parquet files, patch NOW. https://t.co/Z02g16z5eD

    @achi_tech

    8 Apr 2025

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 🚨Nueva vulnerabilidad: CVE-2025-30065 en la librería Java de Apache Parquet (CVSS 10.0) permite a atacantes ejecutar código arbitrario a través de ficheros manipulados. Si tus pipelines procesan archivos Parquet de fuentes no confiables, parchea. Más info aquí:

    @Cyph3R_CyberSec

    7 Apr 2025

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Apache Parquetで重大な脆弱性、対象者はアップデートを(CVE-2025-30065) #セキュリティ対策Lab #セキュリティ #Security https://t.co/L2iK6W67hR

    @securityLab_jp

    7 Apr 2025

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. こんばんは、いかがお過ごしでしょうか「今宵のサイバーセキュリティーについて気になること」情シス部門のゼロトラスト導入に向けて#7 改善活動について考えてみよう、Oracle社が情報漏洩を隠蔽しようとした疑惑、Apache Parquet RCE脆弱性CVE-2025-30065 CVSS10.0 などをお伝えします。 https://t.co/MUuyS6aGAo

    @t_nihonmatsu

    6 Apr 2025

    1981 Impressions

    1 Retweet

    10 Likes

    0 Bookmarks

    1 Reply

    1 Quote

  15. Guidance for handling CVE-2025-30065 using Microsoft Security capabilities https://t.co/zWtJ8191S0 #Microsoft #techcommunity

    @MSITTechNews

    6 Apr 2025

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. #exploit 1. CVE-2025-2748: XSS To RCE By Abusing Custom File Handlers - Kentico Xperience CMS https://t.co/bMnlsnb4Vd 2. CVE-2025-44228: AnyDesk RCE PoC https://t.co/vGlZNwGVFD 3. CVE-2025-30065: Apache Parquet RCE https://t.co/0uZP5a053F

    @ksg93rd

    6 Apr 2025

    622 Impressions

    2 Retweets

    11 Likes

    7 Bookmarks

    0 Replies

    0 Quotes

  17. CVE-2025-30065 Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrad… https://t.co/vBDcnQHrMI

    @CVEnew

    5 Apr 2025

    528 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. Vulnerabilidade Crítica no Apache Parquet e Ataques a Servidores Tomcat 1. Vulnerabilidade no Apache Parquet (CVE-2025-30065): - Gravidade: CVSS 10.0 (crítica). - Impacto: Permite execução remota de código arbitrário via arquivos Parquet maliciosos.

    @pedroco53915492

    5 Apr 2025

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. Critical security alert for Apache Parquet users! A new max-severity flaw (CVE-2025-30065) could let attackers execute arbitrary code. Patch to version 1.15.1 immediately! https://t.co/ORamrFK2dw https://t.co/PUUdHZ34Sg

    @troyCyber_

    5 Apr 2025

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. A maximum severity remote code execution (RCE) vulnerability has been discovered impacting all versions of Apache Parquet up to and including 1.15.0. The vulnerability is tracked under CVE-2025-30065 and has a CVSS v4 score of 10.0. https://t.co/R1BMRjM38d https://t.co/Ih0PtvYHT7

    @riskigy

    5 Apr 2025

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. CVE-2025-30065 : ข้อบกพร่อง RCE ความรุนแรงสูงสุดที่ค้นพบในปาร์เก้ Apache ที่ใช้กันอย่างแพร่หลาย https://t.co/MiSlPj6Vin

    @freedomhack101

    5 Apr 2025

    11 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  22. CVE-2025-30065 impacts Apache Parquet #ApacheParaquet #CVE-2025-30065 https://t.co/NAourLz3Zz

    @pravin_karthik

    5 Apr 2025

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. A maximum severity RCE vulnerability (CVSS 10.0) has been discovered, impacting all versions of Apache Parquet <= v1.15.0. CVE-2025-30065 https://t.co/oR9IowMESz

    @t3l3machus

    5 Apr 2025

    827 Impressions

    5 Retweets

    7 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  24. ثغرة جديدة على Apache Parquet CVE-2025-30065 نوعها RCE و مستوى الخطورة 10 🔥 وكل الاصدارات الى 1.15.0 مصابة تم إغلاق الثغرة في تحديث 1.15.1 التحديث مهم جدا https://t.co/hUHQ32aOzV

    @HereHuss

    5 Apr 2025

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. 🚨 Vulnerabilidad crítica en Apache Parquet Java via 1.15.0 ⚠️ CVE-2025-30065 https://t.co/foqYNktm6w https://t.co/uWRXESReNr

    @elhackernet

    4 Apr 2025

    1714 Impressions

    3 Retweets

    7 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. GitHub - bjornhels/CVE-2025-30065: PoC - https://t.co/WYOq1fwxjM

    @piedpiper1616

    4 Apr 2025

    5020 Impressions

    22 Retweets

    60 Likes

    18 Bookmarks

    0 Replies

    1 Quote

  27. ⚠️ A critical #vulnerability (CVE-2025-30065) in Apache Parquet's Java Library could allow remote code execution on vulnerable instances. This issue has a maximum CVSS score of 10.0 🤖 #flaw https://t.co/w7VTsPVylo

    @manuelbissey

    4 Apr 2025

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. A critical vulnerability, CVE-2025-30065, in the Apache Parquet Java library could allow remote code execution, impacting systems that process untrusted Parquet files. With a CVSS score of 10.0, organizations must quickly upgrade to version 1.15.1 to avoid severe threats, incl...

    @CybrPulse

    4 Apr 2025

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  29. 🗞️ Critical RCE Flaw in Apache Parquet Exposes Big Data Systems to Attack A max-severity RCE flaw (CVE-2025-30065) in Apache Parquet up to v1.15.0 threatens big data platforms like Hadoop and cloud services—upgrade to 1.15.1 ASAP to stay safe! There are no active exploits yet,

    @gossy_84

    4 Apr 2025

    68 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. A critical vulnerability designated CVE-2025-30065 has been discovered in Apache Parquet, with a CVSS score of 10.0, potentially allowing attackers to execute malicious code by leveraging vulnerable applications that process Parquet files. Admins are urged to apply the securit...

    @CybrPulse

    4 Apr 2025

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  31. 広く使用されているApache Parquetで最大の重大度のRCE脆弱性が発見される(CVE-2025-30065) https://t.co/qWOI5lHvkV #Security #セキュリティ #ニュース

    @SecureShield_

    4 Apr 2025

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. 📢 CiberSeguridad en menos de 5 minutos 🧱 Apache Parquet vulnerable a RCE – CVE-2025-30065 permite ejecución remota al procesar archivos manipulados; afecta múltiples plataformas de big data. 🎭 Hunters International ahora es World Leaks – Se enfocan en extorsión sin cifrado, h

    @Seifreed

    4 Apr 2025

    508 Impressions

    2 Retweets

    18 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  33. A critical vulnerability (CVE-2025-30065) in Apache Parquet allows remote code execution via crafted files. Affects versions up to 1.15.0; patched in 1.15.1. Risk to data pipelines is significant. ⚠️ #Apache #DataSecurity #USA link: https://t.co/kFP6D7Rejf https://t.co/nEjyRp9Iz

    @TweetThreatNews

    4 Apr 2025

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. A severe vulnerability in Apache Parquet's Java Library (CVE-2025-30065) has been disclosed, rated with a critical CVSS score of 10.0, allowing potential remote code execution through specially crafted Parquet files. While no known attacks have been reported yet, the risk is s...

    @CybrPulse

    4 Apr 2025

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  35. Apache Parquet RCE脆弱性CVE-2025-30065 CVSS10.0信頼できないデータのデシリアライズに起因しており、バージョン 1.15.1 のリリースで修正されました。これは Parquet ファイルをインポートするすべてのデータ パイプラインと分析システムに影響を与える可能性があります。 https://t.co/Si6iFaoydR

    @t_nihonmatsu

    3 Apr 2025

    198 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  36. 🔴 Una vulnerabilidad de ejecución remota de código (RCE) de máxima gravedad (CVE-2025-30065) afecta hoy a todas las versiones de Apache Parquet hasta la 1.15.0 inclusive. 🧉 https://t.co/SebuB1aIX8

    @MarquisioX

    3 Apr 2025

    49 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  37. CVE-2025-30065 (CVSS 10): Critical Vulnerability Discovered in Apache Parquet Java https://t.co/a45n3sq4jz

    @Dinosn

    2 Apr 2025

    2556 Impressions

    8 Retweets

    11 Likes

    6 Bookmarks

    0 Replies

    0 Quotes

  38. 🚨 CVE-2025-30065 ⚠️🔴 CRITICAL (10) 🏢 Apache Software Foundation - Apache Parquet Java 🏗️ 0 🔗 https://t.co/8DUwqaa4ab #CyberCron #VulnAlert #InfoSec https://t.co/0wDNbd69xT

    @cybercronai

    1 Apr 2025

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. [CVE-2025-30065: CRITICAL] Apache Parquet 1.15.0 and earlier versions are vulnerable to arbitrary code execution due to a flaw in the parquet-avro module. Upgrade to version 1.15.1 for a fix.#cybersecurity,#vulnerability https://t.co/bulUKpWxv2 https://t.co/cI4YIHheZN

    @CveFindCom

    1 Apr 2025

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes