Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

David Sacks and a blurred line of government services

Windsurf CEO opens about a “very dark” mood before recognition

For privacy and security, think carefully before granting AI access to your personal data

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » A key flaw in Apache Parquet allows remote attackers to execute arbitrary code
Identity

A key flaw in Apache Parquet allows remote attackers to execute arbitrary code

userBy userApril 4, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

April 4, 2025Ravi LakshmananVulnerability/Cloud Security

Apache Parquet

The Java library in Apache Parquet discloses the largest severity security vulnerability, allowing remote attackers to execute arbitrary code on their sensitive instances.

Apache Parquet is a free, open source column data file format designed for efficient data processing and searching, providing support for complex data, high performance compression, and encoding schemes. It was first released in 2013.

The vulnerability in question is tracked as CVE-2025-30065. There is a CVSS score of 10.0.

Cybersecurity

“Schema analysis in Apache Parquet 1.15.0 and earlier versions of Parquet-Avro modules allows bad actors to execute arbitrary code,” the project maintainer said in its advisory.

According to Endor Labs, for a successful exploitation of a defect, it requires deceiving vulnerable systems to read a parquet file specifically created to obtain code execution.

“This vulnerability could affect the data pipeline and analysis systems that import parquet files, particularly if these files come from external or untrusted sources,” the company said. “Attackers could tamper with files, which could trigger a vulnerability.”

This drawback affects all versions of software up to 1.15.0. Addressed in version 1.15.1. It is believed that Amazon’s Keyi Li discovered and reported the defect.

While there is no evidence that the flaws are being exploited in the wild, the vulnerability in the Apache project has been opportunistically compromised for threat actors and lightning bolts for threat actors seeking to deploy malware.

Last month, a serious security flaw in Apache Tomcat (CVE-2025-24813, CVSS score: 9.8) was subjected to active exploitation within 30 hours of public disclosure.

Cloud security company Aqua said in an analysis published this week that it discovered a new attack campaign targeting Apache Tomcat servers.

Cybersecurity

The payload can also establish persistence and act as a Java-based web shell that allows attackers to run arbitrary Java code on the server.

“In addition, the script is designed to check if the user has root privileges, and in that case it will run two functions that optimize CPU consumption to perform better encryption results.”

Campaigns that affect both Windows and Linux systems may be rated as the work of Chinese-speaking threat actors, as there are Chinese comments in the source code.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleDid Trump’s tariffs kill US-Africa’s preferred trade? | Donald Trump News
Next Article Afghan activists fled the Taliban. Why are they facing deportation? | Pakistan Taliban News
user
  • Website

Related Posts

Next-Gen Digital Identity: How TwinH and Avatars Are Redefining Creation

July 18, 2025

China’s vast tools secretly extract from SMS, GPS data and confiscated mobile phones.

July 18, 2025

UNG0002 group hits Hong Kong China in Pakistan using LNK files and rats in twin campaign

July 18, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

David Sacks and a blurred line of government services

Windsurf CEO opens about a “very dark” mood before recognition

For privacy and security, think carefully before granting AI access to your personal data

Benchmark for Greptile’s Lead Series A lecture, AI Code Reviewer, valued at $100 million, according to sources

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Next-Gen Digital Identity: How TwinH and Avatars Are Redefining Creation

BREAKING: TwinH Set to Revolutionize Legal Processes – Presented Today at ICEX Forum 2025

Building AGI: Zuckerberg Commits Billions to Meta’s Superintelligence Data Center Expansion

ICEX Forum 2025 Opens: FySelf’s TwinH Showcases AI Innovation

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.