A newly disclosed security flaw (CVE-2025-32896) in Apache SeaTunnel enables unauthenticated attackers to execute arbitrary code and access sensitive files via exposed API endpoints.
This critical vulnerability affects versions 2.3.1 through 2.3.10 of the popular data integration platform, requiring immediate remediation to prevent system compromise.
The vulnerability resides in the unsecured REST API v1 endpoint /hazelcast/rest/maps/submit-job, which allows unauthorized job submissions.
Attackers exploit this by injecting malicious parameters into MySQL connection URLs, triggering two attack vectors:
| Vulnerability Aspect | Details |
|---|---|
| CVE ID | CVE-2025-32896 |
| Affected Versions | SeaTunnel ≤ 2.3.10 |
| Attack Vector | Unauthenticated API access |
| CVSS v3 Severity | 6.5 (Medium) |
| Primary Risk | Full server compromise |
The Apache team addressed this vulnerability in version 2.3.11, released May 27, 2025.
Critical steps for mitigation include:
/submit-job endpointsFailure to patch exposes systems to unauthenticated RCE attacks, particularly dangerous in data-intensive environments where SeaTunnel typically operates.
The fixes in 2.3.11 include enhanced access controls and secure API endpoints, with no known workarounds besides upgrading.
This incident underscores the critical importance of securing API endpoints and maintaining timely software updates in data integration platforms.
Organizations using affected versions should prioritize patching to prevent potential data breaches and system takeovers.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates
The post Apache SeaTunnel Vulnerability Enables Unauthorized Deserialization Attacks appeared first on Cyber Security News.
It’s May 4 — a date that happens to sound similar to “May the Force,”…
The Mandalorian & Grogu is coming to theaters on May 22, but before then you…
If you frequently bring several electronics along with you on your travels but you don't…
Disney+ is offering subscribers a free Marvel Rivals skin through its Disney+ Perks program. The…
There has been a ton of buzz around Dishonored's future, following a rather innocuous post…
Capcom wants players to know that old age won't keep Leon Kennedy out of games…
This website uses cookies.