Impact
A flaw in the org.apache.parquet.crypto.keytools package allows a file-controlled KMS URL to be forwarded to a pluggable KmsClient that may not validate the host. If the reader uses a file-controlled URL, an attacker can embed a malicious host in a Parquet file. When the file is read, the client may transmit the KMS token to the attacker’s server, enabling the attacker to decrypt the data keys and recover the file contents. This flaw is an input validation weakness (CWECWE‑918) that can compromise data confidentiality.
Affected Systems
The affected product is Apache Parquet Hadoop from the Apache Software Foundation. Versions 1.12 through 1.18 inclusive are impacted. No other vendors or versions are listed.
Risk and Exploitability
The vulnerability is triggered by a file-controlled configuration parameter; therefore the attacker must supply a crafted Parquet file to the reader. The exploitation does not require the reader to initiate arbitrary network traffic, but the malicious host specified in the file must be reachable by the client. The CVSS score is 8.1, indicating a high severity. An EPSS score of less than 1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, implying a low likelihood of exploitation. If an adversary can place a malicious file on the reader’s file system, the risk of KMS token theft is immediate, especially given the host-validation bypass (CWE‑918). The issue is mitigated by switching KMS URL handling to application control, which forces the reader to use only trusted URLs.
OpenCVE Enrichment