hudi icon indicating copy to clipboard operation
hudi copied to clipboard

[SUPPORT] Upgrade parquet-avro version in Presto bundle

Open aaneja opened this issue 6 months ago • 0 comments

The last published hudi-presto-bundle, 1.0.2, is using parquet-avro version 1.13.1

This unfortunately has two rather bothersome CVEs -

  1. CVE-2025-46762, score 7.1/10 - Apache Parquet Java: Potential malicious code execution from trusted packages in the parquet-avro module when reading an Avro schema from a Parquet file metadata
  2. CVE-2025-30065, score 10/10 - Apache Parquet Avro Module Vulnerable to Arbitrary Code Execution

Upgrading to parquet-avro 1.15.2 should fix these

aaneja avatar May 15 '25 17:05 aaneja