Unauthorized users can perform Arbitrary File Read and Deserialization
attack by submit job using restful api-v1.
# Details
Unauthorized users can access `/hazelcast/rest/maps/submit-job` to submit
job.
An attacker can set extra params in mysql url to perform Arbitrary File
Read and Deserialization attack.
This issue affects Apache SeaTunnel: <=2.3.10
# Fixed
Users are recommended to upgrade to version 2.3.11, and enable restful api-v2 & open https two-way authentication , which fixes the issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18684 | Apache SeaTunnel: Unauthenticated insecure access |
Github GHSA |
GHSA-9x53-gr7p-4qf5 | Apache SeaTunnel: Unauthenticated insecure access |
Tue, 08 Jul 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache seatunnel |
|
| CPEs | cpe:2.3:a:apache:seatunnel:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache
Apache seatunnel |
Fri, 20 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 19 Jun 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 19 Jun 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | # Summary Unauthorized users can perform Arbitrary File Read and Deserialization attack by submit job using restful api-v1. # Details Unauthorized users can access `/hazelcast/rest/maps/submit-job` to submit job. An attacker can set extra params in mysql url to perform Arbitrary File Read and Deserialization attack. This issue affects Apache SeaTunnel: <=2.3.10 # Fixed Users are recommended to upgrade to version 2.3.11, and enable restful api-v2 & open https two-way authentication , which fixes the issue. | |
| Title | Apache SeaTunnel: Unauthenticated insecure access | |
| Weaknesses | CWE-306 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-06-20T13:53:28.835Z
Reserved: 2025-04-12T03:02:04.962Z
Link: CVE-2025-32896
Updated: 2025-06-19T11:04:11.922Z
Status : Analyzed
Published: 2025-06-19T11:15:24.190
Modified: 2025-07-08T13:05:21.833
Link: CVE-2025-32896
No data.
OpenCVE Enrichment
Updated: 2025-06-20T13:24:21Z
EUVD
Github GHSA