CVE-2023-47248 is a critical deserialization of untrusted data vulnerability in PyArrow versions 0.14.0 to 14.0.0, allowing arbitrary code execution when processing untrusted Arrow IPC, Feather, or Parquet data. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating high exploitability, this vulnerability poses a significant risk due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog or showing active exploitation, a Nuclei template for PyArrow Flight RPC RCE exists, and immediate patching to PyArrow 14.0.1 or using the pyarrow-hotfix package is strongly recommended.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.14.0, <= 14.0.0CPE matchmatch criteria | cpe:2.3:a:apache:pyarrow:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.