CVE-2025-30065 | Apache Parquet Java up to 1.15.0 parquet-avro deserialization (Nessus ID 234234 / WID-SEC-2025-1167)
A vulnerability, which was classified as critical, has been found in Apache Parquet Java up to 1.15.0. This impacts an unknown function of the component parquet-avro Module. The manipulation leads to deserialization.
This vulnerability is uniquely identified as CVE-2025-30065. The attack can only be initiated within the local network. No exploit exists.
It is advisable to upgrade the affected component.