parquet-hadoop is vulnerable to Server-Side Request Forgery (SSRF)
81
High Risk
When a reader does not set an application-controlled KMS URL, org.apache.parquet.crypto.keytools forwards the KMS URL stored in the Parquet file to the pluggable KmsClient. A KmsClient that does not check the host then sends the KMS token to whatever host the file names, so a crafted file can steal the token and unwrap the file's data keys. The fix disables file-controlled KMS URLs by default and requires an explicit parameter to read the URL from the file.
You are affected if you are using a version that falls within the vulnerable range and you read encrypted Parquet files with a file-controlled KMS URL and a custom KmsClient that does not validate the host.
parquet-hadoop is vulnerable to Server-Side Request Forgery (SSRF) in versions 1.12.0 - 1.18.0.
Upgrade the org.apache.parquet:parquet-hadoop library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.