https://seclists.org/oss-sec/2025/q1/260: CVE-2025-30065: Apache Parquet Java: Arbitrary code execution in the parquet-avro module when ading an Avro schema from a Parquet file metadata
Published Apr 1, 2025
·Updated
Affected Software
1 affected component
Apache Parquet Java<=1.15.0
Frequently Asked Questions
1
What is the severity of CVE-2025-30065?
CVE-2025-30065 has a high severity due to its potential for arbitrary code execution.
2
How do I fix CVE-2025-30065?
To fix CVE-2025-30065, upgrade to Apache Parquet Java version 1.15.1 or later.
3
Which versions of Apache Parquet Java are affected by CVE-2025-30065?
CVE-2025-30065 affects Apache Parquet Java through version 1.15.0.
4
What type of vulnerability is CVE-2025-30065?
CVE-2025-30065 is an arbitrary code execution vulnerability.
5
Who reported CVE-2025-30065?
CVE-2025-30065 was reported by Keyi Li from Amazon.