CVE-2021-41561: Apache Parquet-MR potential DoS in case of malicious Parquet file
Published Dec 20, 2021
·Updated
Improper Input Validation vulnerability in Parquet-MR of Apache Parquet allows an attacker to DoS by malicious Parquet files. This issue affects Apache Parquet-MR version 1.9.0 and later versions.
Affected Software
4 affected components
Apache Parquet-MR<1.11.2
Apache Parquet-MR>=1.12.0<1.12.2
Apache Parquet Java<1.11.2
Apache Parquet Java>=1.12.0<1.12.2
Event History
Dec 20, 2021
CVE Published
via MITRE·11:20 AM
Data Sourced
via MITRE·11:20 AM
DescriptionWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-41561?
The CVE-2021-41561 vulnerability is classified as a denial of service (DoS) issue.
2
How do I fix CVE-2021-41561?
To fix CVE-2021-41561, upgrade Apache Parquet-MR to version 1.12.2 or later.
3
What versions of Apache Parquet-MR are affected by CVE-2021-41561?
Apache Parquet-MR versions 1.9.0 through 1.11.2 and versions 1.12.0 to 1.12.1 are affected by CVE-2021-41561.
4
What causes the CVE-2021-41561 vulnerability?
CVE-2021-41561 is caused by improper input validation when processing malicious Parquet files.
5
Can CVE-2021-41561 be exploited remotely?
Yes, CVE-2021-41561 can potentially be exploited remotely through the use of specially crafted Parquet files.