目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-73334— Apache Parquet 文件可控KMS URL转发漏洞

一分钟漏洞结论

影响对象
Apache Software Foundation Apache Parquet Hadoop
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

以下是该漏洞描述的中文翻译: Apache Parquet 的 包(版本 1.12 至 1.18)中可能存在以下问题: 该包允许用户通过信封加密机制对 Parquet 文件进行加密,其中数据密钥通过密钥管理服务(KMS)进行包装(加密)。 在读取端,KMS URL 可以由应用程序控制,也可以由文件控制。如果用户未使用应用程序控制来指定该参数,则文件中的 KMS URL 会被传递给可插拔的 实现。如果该可插拔实现未执行主机验证,攻击者可以通过在文件中设置的恶意主机接收 KMS 令牌。 在问题修复之前,建议用户在读取端

AI 预测 5.4 利用难度: 困难
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-73334 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Apache Parquet Hadoop: File-controlled KMS URL is forwarded to pluggable KmsClient that skips host validation
来源: CVE Program / CVE List V5
Vulnerability Description
Potential problem for users of the org.apache.parquet.crypto.keytools package in Apache Parquet, versions 1.12 to 1.18. This package enables users to encrypt Parquet files via an envelope encryption mechanism that wraps (encrypts) data keys via a Key Management Service (KMS).  On the reader side, the KMS URL can be application-controlled or file-controlled. If the user does not leverage application control for this parameter, a file-controlled KMS URL is forwarded to a pluggable KmsClient implementation. If the pluggable implementation does not perform host validation, a KMS token can be sent to a malicious host set by an attacker in the file. Before the problem is fixed, users are recommended to leverage application control for KMS URL parameter in readers (versions 1.12-1.18). After the problem is fixed (presumably in version 1.19), the upgrade will disable file-controlled KMS URL by default. Users of the KMS URL parameter  will have two options then: leverage application control for KMS URL parameter in readers, or enable file-controlled KMS URL (via a new app parameter). The latter option will explicitly require (in the new parameter documentation) to validate the KMS URL and use authentication in the custom implementation of the KMS client plug in.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
输入验证不恰当
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Apache Software Foundation Apache Parquet Hadoop 1.12 ~ 1.18.0 -

二、漏洞 CVE-2026-73334 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-73334 的情报信息

登录查看更多情报信息。

CVE-2026-73334 邮件列表归档 (1)

同批安全公告 · Apache Software Foundation · 2026-09-09 · 共 9 条

CVE-2026-74761 Apache ActiveMQ 任意版本 客户端ID欺骗漏洞
CVE-2026-41871 Apache Nutch 服务器未授权反射式任务执行漏洞
CVE-2026-41869 Apache Nutch 未认证强制关机及作业中断漏洞
CVE-2026-41870 Apache Nutch 服务端 JEXL 注入致远程代码执行
CVE-2026-65181 Apache Impala 远程代码执行漏洞
CVE-2026-57866 Apache Impala 服务端请求伪造漏洞
CVE-2026-56207 Apache Impala 通过伪造Bearer令牌绕过SAML身份验证漏洞
CVE-2026-54048 Apache Impala Avro 服务器端请求伪造漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-73334

暂无评论


发表评论