PT-2025-16173 · Apache · Apache Seatunnel

Liyiwei

+1

·

Published

2025-04-12

·

Updated

2025-06-20

·

CVE-2025-32896

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache SeaTunnel versions <=2.3.10
Description Unauthorized users can perform Arbitrary File Read and Deserialization attack by submitting a job using the restful api-v1. An attacker can access the /hazelcast/rest/maps/submit-job endpoint to submit a job and set extra parameters in the MySQL URL to perform the attack.
Recommendations For Apache SeaTunnel versions <=2.3.10, users are recommended to upgrade to version 2.3.11 and enable restful api-v2 and open https two-way authentication, which fixes the issue. As a temporary workaround, consider restricting access to the /hazelcast/rest/maps/submit-job endpoint until the issue is resolved.

Fix

RCE

Missing Authentication

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2025-05056
CVE-2025-32896
GHSA-9X53-GR7P-4QF5

Affected Products

Apache Seatunnel