GCP Weekly[verified]@gcpweeklyPatch
The message announces that multiple CVEs (CVE-2025-58057, CVE-2025-53864, CVE-2025-68161, CVE-2025-48924, CVE-2025-33042) have been fixed in updated Dataproc Metastore Proxy packages.
GCP Weekly[verified]@gcpweeklyPatch
The listed software versions have been updated, applying fixes for several CVEs; no additional exploit or PoC information is provided.
GCP Weekly[verified]@gcpweeklyPatch
The post announces that hms-proxy has been upgraded to version 0.0.78 to remediate CVEs, indicating a patch has been applied.
Open Source Security mailing list@oss_securityDisclosure
A moderate‑severity code injection vulnerability (CVE‑2025‑33042) exists in the Apache Avro Java SDK when processing untrusted schemas; technical details are noted and a link to a mailing‑list discussion is provided.
cvereports@_cvereportsDisclosure
The report announces a critical code injection vulnerability in Apache Avro's Java SDK, but offers no PoC, exploit details, or mitigation information.
Vulmon Vulnerability Feed@VulmonFeedsGeneral
The content merely repeats the CVE identifier and provides generic links to a vulnerability details page, without any specific technical or actionable information.
CRAC Learning - Tech@cracbotDisclosure
The tweet announces the CVE-2025-33042 vulnerability, providing its CVSS rating, type, and affected software, but no PoC, exploit, or patch details are supplied.
TRONCAL Yannick@ytroncalDisclosure
The article announces CVE‑2025‑33042, a code‑injection flaw in Apache Avro, but provides no details on exploitation, patching, or PoC evidence.