Fixed CVEs in Flow Management
Review the list of common vulnerabilities and exposures fixed in Cloudera Flow Management (CFM) 2.2.7 in Data Hub in CDP Public Cloud 7.2.17.
- CVE-2025-30065 - Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
- Apache Parquet Java: Arbitrary code execution in the parquet-avro module when reading an Avro schema from a Parquet file metadata
- CVE-2023-34212
- The JndiJmsConnectionFactoryProvider Controller Service, along with the ConsumeJMS and PublishJMS Processors, in Apache NiFi 1.8.0 through 1.21.0 allow an authenticated and authorized user to configure URL and library properties that enable deserialization of untrusted data from a remote location. The resolution validates the JNDI URL and restricts locations to a set of allowed schemes. You are recommended to upgrade to version 1.22.0 or later which fixes this issue. For more information, see Behavioral changes.
