<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Apache Parquet &amp;lt; 1.15.1 Remote Code Execution (CVE-2025-30065) in ArcGIS Pro in ArcGIS Pro Questions</title>
    <link>https://community.esri.com/t5/arcgis-pro-questions/apache-parquet-lt-1-15-1-remote-code-execution-cve/m-p/1613455#M95689</link>
    <description>&lt;P&gt;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/2892"&gt;@RandallWilliams&lt;/a&gt;&amp;nbsp;; the Trust Site is showing this CVE as "Esri Assessment &amp;amp; Response:&lt;BR /&gt;Component not present" ; but Tenable is scanning the jar files in the Pro installation folder and returning this:&lt;/P&gt;&lt;P&gt;Plugin Output:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;Path&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : C:\Program Files\ArcGIS\Pro\java\runtime\spark\jars\parquet-column-1.13.1.jar&lt;/P&gt;&lt;P&gt;&amp;nbsp; Installed version : 1.13.1&lt;/P&gt;&lt;P&gt;&amp;nbsp; Fixed version&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1.15.1&lt;/P&gt;&lt;P&gt;&amp;nbsp; Path&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : C:\Program Files\ArcGIS\Pro\java\runtime\spark\jars\parquet-common-1.13.1.jar&lt;/P&gt;&lt;P&gt;&amp;nbsp; Installed version : 1.13.1&lt;/P&gt;&lt;P&gt;&amp;nbsp; Fixed version&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1.15.1&lt;/P&gt;&lt;P&gt;&amp;nbsp; Path&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : C:\Program Files\ArcGIS\Pro\java\runtime\spark\jars\parquet-encoding-1.13.1.jar&lt;/P&gt;&lt;P&gt;&amp;nbsp; Installed version : 1.13.1&lt;/P&gt;&lt;P&gt;&amp;nbsp; Fixed version&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1.15.1&lt;/P&gt;&lt;P&gt;&amp;nbsp; Path&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : C:\Program Files\ArcGIS\Pro\java\runtime\spark\jars\parquet-hadoop-1.13.1.jar&lt;/P&gt;&lt;P&gt;&amp;nbsp; Installed version : 1.13.1&lt;/P&gt;&lt;P&gt;&amp;nbsp; Fixed version&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1.15.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 09 May 2025 22:29:35 GMT</pubDate>
    <dc:creator>DEWright_CA</dc:creator>
    <dc:date>2025-05-09T22:29:35Z</dc:date>
    <item>
      <title>Apache Parquet &lt; 1.15.1 Remote Code Execution (CVE-2025-30065) in ArcGIS Pro</title>
      <link>https://community.esri.com/t5/arcgis-pro-questions/apache-parquet-lt-1-15-1-remote-code-execution-cve/m-p/1613455#M95689</link>
      <description>&lt;P&gt;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/2892"&gt;@RandallWilliams&lt;/a&gt;&amp;nbsp;; the Trust Site is showing this CVE as "Esri Assessment &amp;amp; Response:&lt;BR /&gt;Component not present" ; but Tenable is scanning the jar files in the Pro installation folder and returning this:&lt;/P&gt;&lt;P&gt;Plugin Output:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;Path&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : C:\Program Files\ArcGIS\Pro\java\runtime\spark\jars\parquet-column-1.13.1.jar&lt;/P&gt;&lt;P&gt;&amp;nbsp; Installed version : 1.13.1&lt;/P&gt;&lt;P&gt;&amp;nbsp; Fixed version&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1.15.1&lt;/P&gt;&lt;P&gt;&amp;nbsp; Path&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : C:\Program Files\ArcGIS\Pro\java\runtime\spark\jars\parquet-common-1.13.1.jar&lt;/P&gt;&lt;P&gt;&amp;nbsp; Installed version : 1.13.1&lt;/P&gt;&lt;P&gt;&amp;nbsp; Fixed version&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1.15.1&lt;/P&gt;&lt;P&gt;&amp;nbsp; Path&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : C:\Program Files\ArcGIS\Pro\java\runtime\spark\jars\parquet-encoding-1.13.1.jar&lt;/P&gt;&lt;P&gt;&amp;nbsp; Installed version : 1.13.1&lt;/P&gt;&lt;P&gt;&amp;nbsp; Fixed version&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1.15.1&lt;/P&gt;&lt;P&gt;&amp;nbsp; Path&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : C:\Program Files\ArcGIS\Pro\java\runtime\spark\jars\parquet-hadoop-1.13.1.jar&lt;/P&gt;&lt;P&gt;&amp;nbsp; Installed version : 1.13.1&lt;/P&gt;&lt;P&gt;&amp;nbsp; Fixed version&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1.15.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 May 2025 22:29:35 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-pro-questions/apache-parquet-lt-1-15-1-remote-code-execution-cve/m-p/1613455#M95689</guid>
      <dc:creator>DEWright_CA</dc:creator>
      <dc:date>2025-05-09T22:29:35Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Parquet &lt; 1.15.1 Remote Code Execution (CVE-2025-30065) in ArcGIS Pro</title>
      <link>https://community.esri.com/t5/arcgis-pro-questions/apache-parquet-lt-1-15-1-remote-code-execution-cve/m-p/1613496#M95699</link>
      <description>&lt;P&gt;The CVE seems to concern only one specific library regarding Avro format, which doesn't seem present in the Pro install (see my listing below which slightly differs from yours but does not show a file name with 'avro'). These found modules are different ones, and as far as I can tell not involved in the CVE. I guess the affected module is called simply 'parquet-avro-&amp;lt;VERSION&amp;gt;.jar', but I didn't see the actual full filename listed in the CVE.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MarcoBoeringa_0-1746899075166.png" style="width: 400px;"&gt;&lt;img src="https://community.esri.com/t5/image/serverpage/image-id/131937iD1E75C3ACB7B74B1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="MarcoBoeringa_0-1746899075166.png" alt="MarcoBoeringa_0-1746899075166.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 10 May 2025 17:49:59 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-pro-questions/apache-parquet-lt-1-15-1-remote-code-execution-cve/m-p/1613496#M95699</guid>
      <dc:creator>MarcoBoeringa</dc:creator>
      <dc:date>2025-05-10T17:49:59Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Parquet &lt; 1.15.1 Remote Code Execution (CVE-2025-30065) in ArcGIS Pro</title>
      <link>https://community.esri.com/t5/arcgis-pro-questions/apache-parquet-lt-1-15-1-remote-code-execution-cve/m-p/1613652#M95716</link>
      <description>&lt;P&gt;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/15724"&gt;@MarcoBoeringa&lt;/a&gt;&amp;nbsp;is correct and Tenable is providing a false positive. We do not provide&amp;nbsp;&lt;SPAN&gt;the parquet-avro module. Tenable chooses to err on the side of false positives over false negatives.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;"Esri Assessment &amp;amp; Response:&lt;BR /&gt;Component not present"&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is the correct response.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2025 14:33:39 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-pro-questions/apache-parquet-lt-1-15-1-remote-code-execution-cve/m-p/1613652#M95716</guid>
      <dc:creator>RandallWilliams</dc:creator>
      <dc:date>2025-05-12T14:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Parquet &lt; 1.15.1 Remote Code Execution (CVE-2025-30065) in ArcGIS Pro</title>
      <link>https://community.esri.com/t5/arcgis-pro-questions/apache-parquet-lt-1-15-1-remote-code-execution-cve/m-p/1613832#M95732</link>
      <description>&lt;P&gt;Thank you for the additional detail; I have forwarded this thread to my security team.&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2025 22:12:51 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-pro-questions/apache-parquet-lt-1-15-1-remote-code-execution-cve/m-p/1613832#M95732</guid>
      <dc:creator>DEWright_CA</dc:creator>
      <dc:date>2025-05-12T22:12:51Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Parquet &lt; 1.15.1 Remote Code Execution (CVE-2025-30065) in ArcGIS Pro</title>
      <link>https://community.esri.com/t5/arcgis-pro-questions/apache-parquet-lt-1-15-1-remote-code-execution-cve/m-p/1666274#M100179</link>
      <description>&lt;P&gt;We got it on server, do you have an update for this?&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;STRONG&gt;Description:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;The version of Apache Parquet on the remote host is prior to 1.15.1. It is, therefore, affected by a remote code execution vulnerability:&lt;/P&gt;&lt;UL class=""&gt;&lt;LI&gt;Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrade to version 1.15.1, which fixes the issue. (CVE-2025-30065)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;BR /&gt;**************&lt;BR /&gt;&lt;STRONG&gt;Plugin Title:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Apache Parquet &amp;lt; 1.15.1 Remote Code Execution (CVE-2025-30065)&lt;BR /&gt;&lt;BR /&gt;**************&lt;BR /&gt;&lt;STRONG&gt;Plugin Output:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL class=""&gt;&lt;LI&gt;Path : C:\Program Files\ArcGIS\Server\framework\runtime\spark\jars\parquet-hadoop-1.13.1.jar&lt;/LI&gt;&lt;LI&gt;Installed version : 1.13.1&lt;/LI&gt;&lt;LI&gt;Fixed version : 1.15.1&lt;/LI&gt;&lt;/UL&gt;&lt;UL class=""&gt;&lt;LI&gt;Path : C:\Program Files\ArcGIS\Server\framework\runtime\spark\jars\parquet-encoding-1.13.1.jar&lt;/LI&gt;&lt;LI&gt;Installed version : 1.13.1&lt;/LI&gt;&lt;LI&gt;Fixed version : 1.15.1&lt;/LI&gt;&lt;/UL&gt;&lt;UL class=""&gt;&lt;LI&gt;Path : C:\Program Files\ArcGIS\Server\framework\runtime\spark\jars\parquet-column-1.13.1.jar&lt;/LI&gt;&lt;LI&gt;Installed version : 1.13.1&lt;/LI&gt;&lt;LI&gt;Fixed version : 1.15.1&lt;/LI&gt;&lt;/UL&gt;&lt;UL class=""&gt;&lt;LI&gt;Path : C:\Program Files\ArcGIS\Server\framework\runtime\spark\jars\parquet-common-1.13.1.jar&lt;/LI&gt;&lt;LI&gt;Installed version : 1.13.1&lt;/LI&gt;&lt;LI&gt;Fixed version : 1.15.1&lt;BR /&gt;**************&lt;BR /&gt;&lt;STRONG&gt;CVE(s):&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;CVE-2025-30065&lt;/LI&gt;&lt;/UL&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Mon, 17 Nov 2025 15:01:37 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-pro-questions/apache-parquet-lt-1-15-1-remote-code-execution-cve/m-p/1666274#M100179</guid>
      <dc:creator>TKSHEP</dc:creator>
      <dc:date>2025-11-17T15:01:37Z</dc:date>
    </item>
    <item>
      <title>Re: Apache Parquet &lt; 1.15.1 Remote Code Execution (CVE-2025-30065) in ArcGIS Pro</title>
      <link>https://community.esri.com/t5/arcgis-pro-questions/apache-parquet-lt-1-15-1-remote-code-execution-cve/m-p/1666277#M100180</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'd argue that there is a bug in your tooling.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This finding as against the&amp;nbsp;&lt;SPAN&gt;parquet-avro module, which is not in the list of JARS the tool you've provided.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Nov 2025 15:06:27 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-pro-questions/apache-parquet-lt-1-15-1-remote-code-execution-cve/m-p/1666277#M100180</guid>
      <dc:creator>RandallWilliams</dc:creator>
      <dc:date>2025-11-17T15:06:27Z</dc:date>
    </item>
  </channel>
</rss>

