Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

“Fragile Space” exhibition highlights the dangers of space debris

Google fixes two active Chrome zero-days affecting Skia and V8

Elestor’s hydrogen-iron flow batteries have a 25-year shelf life

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » A key flaw in Apache Parquet allows remote attackers to execute arbitrary code
Identity

A key flaw in Apache Parquet allows remote attackers to execute arbitrary code

userBy userApril 4, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

April 4, 2025Ravi LakshmananVulnerability/Cloud Security

Apache Parquet

The Java library in Apache Parquet discloses the largest severity security vulnerability, allowing remote attackers to execute arbitrary code on their sensitive instances.

Apache Parquet is a free, open source column data file format designed for efficient data processing and searching, providing support for complex data, high performance compression, and encoding schemes. It was first released in 2013.

The vulnerability in question is tracked as CVE-2025-30065. There is a CVSS score of 10.0.

Cybersecurity

“Schema analysis in Apache Parquet 1.15.0 and earlier versions of Parquet-Avro modules allows bad actors to execute arbitrary code,” the project maintainer said in its advisory.

According to Endor Labs, for a successful exploitation of a defect, it requires deceiving vulnerable systems to read a parquet file specifically created to obtain code execution.

“This vulnerability could affect the data pipeline and analysis systems that import parquet files, particularly if these files come from external or untrusted sources,” the company said. “Attackers could tamper with files, which could trigger a vulnerability.”

This drawback affects all versions of software up to 1.15.0. Addressed in version 1.15.1. It is believed that Amazon’s Keyi Li discovered and reported the defect.

While there is no evidence that the flaws are being exploited in the wild, the vulnerability in the Apache project has been opportunistically compromised for threat actors and lightning bolts for threat actors seeking to deploy malware.

Last month, a serious security flaw in Apache Tomcat (CVE-2025-24813, CVSS score: 9.8) was subjected to active exploitation within 30 hours of public disclosure.

Cloud security company Aqua said in an analysis published this week that it discovered a new attack campaign targeting Apache Tomcat servers.

Cybersecurity

The payload can also establish persistence and act as a Java-based web shell that allows attackers to run arbitrary Java code on the server.

“In addition, the script is designed to check if the user has root privileges, and in that case it will run two functions that optimize CPU consumption to perform better encryption results.”

Campaigns that affect both Windows and Linux systems may be rated as the work of Chinese-speaking threat actors, as there are Chinese comments in the source code.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleDid Trump’s tariffs kill US-Africa’s preferred trade? | Donald Trump News
Next Article Afghan activists fled the Taliban. Why are they facing deportation? | Pakistan Taliban News
user
  • Website

Related Posts

Google fixes two active Chrome zero-days affecting Skia and V8

March 13, 2026

9 CrackArmor flaws in Linux AppArmor allow route escalation and bypass container isolation

March 13, 2026

Authorities disrupt SocksEscort proxy botnet exploiting 369,000 IPs in 163 countries

March 13, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

“Fragile Space” exhibition highlights the dangers of space debris

Google fixes two active Chrome zero-days affecting Skia and V8

Elestor’s hydrogen-iron flow batteries have a 25-year shelf life

Destroying PFAS: Challenges, threats, and opportunities

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.