article thumbnail

Critical flaw in Apache Parquet’s Java Library allows remote code execution

Security Affairs

Experts warn of a critical vulnerability impacting Apache Parquet’s Java Library that could allow remote code execution. Apache Parquet’s Java Library is a software library for reading and writing Parquet files in the Java programming language. The researchers urge users to address the issue immediately.

Libraries 169
article thumbnail

Google fixed the first actively exploited Chrome zero-day since the start of the year

Security Affairs

Google has released out-of-band fixes to address a high-severity security vulnerability, tracked as CVE-2025-2783 , in Chrome browser for Windows. Kaspersky researchers Boris Larin (@oct0xor) and Igor Kuznetsov (@2igosha) reported the vulnerability on March 20, 2025. ” reads the advisory published by Google.

Libraries 291
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

GitLab addressed critical auth bypass flaws in CE and EE

Security Affairs

The company addressed nine vulnerabilities, including the two critical ruby-saml authentication bypass issues respectively tracked as CVE-2025-25291 and CVE-2025-25292. This library is, however, used in other popular projects and products.” GitLab CE/EE versions 17.7.7, addressed the issue. GitLab.com is already patched.

article thumbnail

Critical Apache Roller flaw allows to retain unauthorized access even after a password change

Security Affairs

A critical flaw (CVE-2025-24859, CVSS 10) in Apache Roller lets attackers keep access even after password changes. A critical vulnerability, tracked as CVE-2025-24859 (CVSS score of 10.0), affects the Apache Roller open-source, Java-based blogging server software. All versions 6.1.4 are affected.

Passwords 127
article thumbnail

Libraries Week: Libraries Change Lives in June and Green Libraries Week in October

CILIP

Libraries Week: Libraries Change Lives in June and Green Libraries Week in October SAVE THE DATES 2025: Libraries Change Lives will take place in June and Green Libraries Week in October. The new annual programme for campaigns is: Libraries Week: Libraries Change Lives , Monday 2 June Sunday 8 June 2025.

article thumbnail

Invitation to tender: Future ready libraries

CILIP

Invitation to tender: Future ready libraries CILIP is inviting researchers to undertake a gap analysis and consultation with sector experts to create a comprehensive review of training provision for leadership in the public library workforce in England. Contact Hinna Vayani for more details.

article thumbnail

Appsec Roundup - March 2025

Adam Shostack

Appsec The International Obfuscated C Code Contest has announced The 40th anniversary of the IOCCC, IOCCC28, (are) open for submissions from 2025-03-05 23:19:17.131107 UTC to 2025-06-05 04:03:02.010099 UTC. Image by Midjourney: a photograph of a robot, sitting in a library, working on a jigsaw puzzle