[
https://issues.apache.org/jira/browse/FLINK-37609?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17941266#comment-17941266
]
Ferenc Csaky commented on FLINK-37609:
--------------------------------------
This is quite a critical CVE, shouldn't we backport this to all currently
active versions?
> Bump parquet libs to 1.15.1
> ---------------------------
>
> Key: FLINK-37609
> URL: https://issues.apache.org/jira/browse/FLINK-37609
> Project: Flink
> Issue Type: Bug
> Components: Formats (JSON, Avro, Parquet, ORC, SequenceFile)
> Affects Versions: 2.0.0, 1.19.2, 1.20.1, 2.0-preview
> Reporter: Sergey Nuyanzin
> Assignee: Sergey Nuyanzin
> Priority: Major
> Labels: pull-request-available
> Fix For: 2.1.0
>
>
> There is vulnerability for parquet-avro
> https://nvd.nist.gov/vuln/detail/CVE-2025-30065
--
This message was sent by Atlassian Jira
(v8.20.10#820010)