AI description
CVE-2025-32896 affects Apache SeaTunnel, a distributed data integration platform. Specifically, versions 2.3.1 through 2.3.10 are vulnerable. The vulnerability stems from unauthenticated access to the `/hazelcast/rest/maps/submit-job` REST API endpoint. Attackers can exploit this vulnerability by injecting malicious parameters into a MySQL connection URL via the REST API. This allows for arbitrary file read and deserialization attacks. To mitigate this issue, users are advised to upgrade to version 2.3.11 and enable restful API-v2 along with two-way HTTPS authentication.
- Description
- # Summary Unauthorized users can perform Arbitrary File Read and Deserialization attack by submit job using restful api-v1. # Details Unauthorized users can access `/hazelcast/rest/maps/submit-job` to submit job. An attacker can set extra params in mysql url to perform Arbitrary File Read and Deserialization attack. This issue affects Apache SeaTunnel: <=2.3.10 # Fixed Users are recommended to upgrade to version 2.3.11, and enable restful api-v2 & open https two-way authentication , which fixes the issue.
- Source
- security@apache.org
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 6.5
- Impact score
- 3.6
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity
- MEDIUM
- security@apache.org
- CWE-306
- Hype score
- Not currently trending
New flaw in Apache SeaTunnel (CVE-2025-32896): attackers can run code via its REST API—no login needed. 😱 Paxion Cyber locks down APIs, detects injection threats & protects Java-based data flows. 🔐 Upgrade. Harden. Monitor. #CyberTipFriday Don’t leave old APIs liv
@PaxionCyber
20 Jun 2025
38 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-32896: Apache SeaTunnel Flaw Enables Unauthenticated File Read & RCE https://t.co/4QtJECskvC
@Dinosn
13 Apr 2025
2951 Impressions
5 Retweets
28 Likes
6 Bookmarks
0 Replies
0 Quotes
CVE-2025-32896 CVE-2025-32896 https://t.co/fduE92rtpX Vulnerability Alert Subscriptions: https://t.co/hrQhy5uz4x
@VulmonFeeds
12 Apr 2025
70 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-32896: Apache SeaTunnel: Unauthenticated insecure access https://t.co/wcIw5BJCgv Severity: moderate Arbitrary File Read and Deserialization attack by submitting job using restful api-v1. Upgrade to 2.3.11, and enable restful api-v2 & open https two-way authentication
@oss_security
12 Apr 2025
277 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes