以下是该漏洞描述的中文翻译: Apache Parquet 的 包(版本 1.12 至 1.18)中可能存在以下问题: 该包允许用户通过信封加密机制对 Parquet 文件进行加密,其中数据密钥通过密钥管理服务(KMS)进行包装(加密)。 在读取端,KMS URL 可以由应用程序控制,也可以由文件控制。如果用户未使用应用程序控制来指定该参数,则文件中的 KMS URL 会被传递给可插拔的 实现。如果该可插拔实现未执行主机验证,攻击者可以通过在文件中设置的恶意主机接收 KMS 令牌。 在问题修复之前,建议用户在读取端
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Parquet Hadoop | 1.12 ~ 1.18.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74761 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of RemoveSubscripti | |
| CVE-2026-41871 | Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST A | |
| CVE-2026-41869 | Apache Nutch: Unauthenticated forced shutdown and job interruption in Nutch Server (Nutch | |
| CVE-2026-41870 | Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch Serv | |
| CVE-2026-65181 | Apache Impala: RCE via External Data Source Class Loading | |
| CVE-2026-57866 | Apache Impala: Secrets Exfiltration via SSRF | |
| CVE-2026-56207 | Apache Impala: SAML authentication bypass via forged bearer token | |
| CVE-2026-54048 | Apache Impala: Avro Schema URL Server-Side Request Forgery |
No comments yet