CVE-2025-32896

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
19/06/2025
Last modified:
08/07/2025

Description

# Summary<br /> <br /> Unauthorized users can perform Arbitrary File Read and Deserialization<br /> attack by submit job using restful api-v1.<br /> <br /> # Details<br /> Unauthorized users can access `/hazelcast/rest/maps/submit-job` to submit<br /> job.<br /> An attacker can set extra params in mysql url to perform Arbitrary File<br /> Read and Deserialization attack.<br /> <br /> This issue affects Apache SeaTunnel:

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:seatunnel:*:*:*:*:*:*:*:* 2.3.1 (including) 2.3.11 (excluding)